VYPR
Moderate severityNVD Advisory· Published Oct 25, 2023· Updated Feb 13, 2025

CVE-2023-46652

CVE-2023-46652

Description

The lambdatest-automation Plugin 1.20.9 and earlier fails to check permissions in an HTTP endpoint, allowing attackers with Overall/Read to enumerate credential IDs of LAMBDATEST credentials stored in Jenkins.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

The lambdatest-automation Plugin 1.20.9 and earlier fails to check permissions in an HTTP endpoint, allowing attackers with Overall/Read to enumerate credential IDs of LAMBDATEST credentials stored in Jenkins.

Vulnerability

Description

The Jenkins lambdatest-automation Plugin 1.20.9 and earlier contains a missing permission check in an HTTP endpoint. This flaw allows an attacker who already has the Overall/Read permission to enumerate credential IDs of LAMBDATEST credentials stored in Jenkins [1][2]. The plugin does not properly authorize the endpoint, leading to the unintentional exposure of sensitive identifiers.

Exploitation and

Attack Surface

An attacker must possess Overall/Read permission to exploit this vulnerability. The attack is performed over the network by sending a crafted HTTP request to the vulnerable endpoint [1]. No other authentication or privileges are needed. The attacker can then enumerate the credential IDs, which can be used as part of a chained attack to capture the actual credentials using another vulnerability in the same plugin [1].

Impact

While the severity is rated Medium (CVSS v3 base score not provided), the impact is significant as it enables attackers to discover credential IDs and use them in further exploitation to potentially leak credentials [1][2]. The enumeration of credential IDs is a stepping stone for more severe attacks.

Mitigation

The vulnerability is patched in lambdatest-automation Plugin version 1.20.10 and 1.21.0 [1][3]. In the fixed version, enumeration of credential IDs requires Overall/Administer permission [1][2]. Users should immediately upgrade to either of these versions to close the attack vector.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.jenkins-ci.plugins:lambdatest-automationMaven
< 1.20.101.20.10

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

1