Intel

AIKIDO-2026-214219

scm-manager is vulnerable to Missing Authorization

Missing AuthorizationCVE-2026-70435 Published 3 days ago

42

Medium Risk

This Affects:

JAVAscm-manager
0.0.1 - 1.11.1
Fixed in 1.12.1
Are you affected? Scan for Free

TL;DR

Several HTTP endpoints skip permission checks when connecting to attacker-specified HTTP URLs with attacker-specified credentials IDs. An attacker with Overall/Read permission can capture credentials stored in Jenkins. The fix requires Item/Configure permission on those endpoints.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and users with Overall/Read permission can reach the plugin HTTP endpoints.

Background info

scm-manager is vulnerable to Missing Authorization in versions 0.0.1 - 1.11.1.

How to fix this

Upgrade the io.jenkins.plugins:scm-manager library to the patch version.