BlazeMeter Jenkins Plugin is Missing Authorization for Available Resources
Moderate severity
GitHub Reviewed
Published
Dec 3, 2025
to the GitHub Advisory Database
•
Updated Dec 3, 2025
Package
Affected versions
< 4.27
Patched versions
4.27
Description
Published by the National Vulnerability Database
Dec 3, 2025
Published to the GitHub Advisory Database
Dec 3, 2025
Reviewed
Dec 3, 2025
Last updated
Dec 3, 2025
A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like credential IDs, bzm workspaces and bzm project Ids. Prior to this fix, anyone could see this list as a dropdown on the Jenkins UI.
References