CVE-2025-24400

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/01/2025
Last modified:
03/10/2025

Description

Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event published to RabbitMQ with the legitimate credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:eiffel_broadcaster:*:*:*:*:*:jenkins:*:* 2.8.0 (including) 2.10.2 (including)


References to Advisories, Solutions, and Tools