VYPR

GitLab Plugin

by Jenkins Project

Source repositories

CVEs (2)

  • CVE-2026-92133MedSep 16, 2026
    risk 0.35cvss 5.4epss 0.00

    Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials under a cache key derived from the credentials ID alone, omitting the folder in which the credentials are resolved, allowing attackers with…

  • CVE-2026-84664MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through Stapler data binding, allowing attackers to connect to an attacker-specified URL using GitLab API tokens already configured by administrators.