CyberRota Analysis
AI-GeneratedThe Jenkins GitLab Plugin versions 1.9.16 and earlier are vulnerable to a configuration overwrite that enables attackers to manipulate the global GitLab connection settings via Stapler data binding. This flaw allows unauthorized connections to arbitrary URLs using existing GitLab API tokens, potentially compromising sensitive data and access. Organizations using these versions of the Jenkins GitLab Plugin should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators.