Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26514 | A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b_92b_cd64 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. |
Github GHSA |
GHSA-f696-867g-2759 | Jenkins OpenTelemetry Plugin missing permission check allows capturing credentials |
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 09 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins opentelemetry
|
|
| CPEs | cpe:2.3:a:jenkins:opentelemetry:*:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins opentelemetry
|
Thu, 04 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins jenkins |
|
| Vendors & Products |
Jenkins
Jenkins jenkins |
Wed, 03 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Wed, 03 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b_92b_cd64 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-11-04T21:13:45.952Z
Reserved: 2025-09-02T12:44:16.983Z
Link: CVE-2025-58460
Updated: 2025-11-04T21:13:45.952Z
Status : Modified
Published: 2025-09-03T15:15:39.793
Modified: 2025-11-04T22:16:34.507
Link: CVE-2025-58460
No data.
OpenCVE Enrichment
Updated: 2025-09-04T13:12:28Z
EUVD
Github GHSA