Executive brief
The Jenkins Zowe zDevOps plugin, which integrates Jenkins with Zowe mainframe services, contains a security flaw where it fails to verify user permissions for certain actions. This allows an authorized Jenkins user to trick the system into connecting to a malicious server using existing credentials stored in Jenkins. An attacker could use this to steal sensitive login information or service credentials, potentially compromising connected mainframe systems.
Technical details
A missing permission check in Jenkins Zowe zDevOps Plugin version 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to trigger an outbound connection to an arbitrary URL. By specifying a malicious endpoint and a known credential ID (obtained through other means), the attacker can cause the plugin to transmit Jenkins-stored credentials to the external server. This is a classic credential capture vulnerability resulting from improper authorization on a diagnostic or connection-testing endpoint. As of the advisory date, users should check for updates to the Zowe zDevOps Plugin.
Affected products
- Jenkins Project Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory