GHSA-98m4-m2c3-qxgq
GitHub Security Advisory
Jenkins JIRA Plugin allows users to select and use credentials with System scope
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and use credentials with System scope. Jira Plugin 3.0.11 defines the appropriate folder context for credential lookup. As a side effect, existing per-folder Jira sites may lose access to already configured System-scoped credentials, as if no credential was specified in the first place.
Affected Packages
Maven
org.jenkins-ci.plugins:jira
Affected versions:
0
(fixed in 3.0.11)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 3, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.