From abbe4976c3ba9470a4d6cbde517b01a37c5f31d2 Mon Sep 17 00:00:00 2001 From: ai-anant Date: Sun, 13 Sep 2026 03:16:10 +0530 Subject: [PATCH] feat(java): detect CredentialsProvider.lookupCredentials with null authentication (CWE-522) A null Authentication argument is treated as ACL.SYSTEM by the Credentials plugin, so the lookup returns secrets the caller and current item may not be allowed to use. --- .../lookup-null-authentication.yaml | 29 +++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 java/jenkins/credentials/lookup-null-authentication.yaml diff --git a/java/jenkins/credentials/lookup-null-authentication.yaml b/java/jenkins/credentials/lookup-null-authentication.yaml new file mode 100644 index 0000000..f813870 --- /dev/null +++ b/java/jenkins/credentials/lookup-null-authentication.yaml @@ -0,0 +1,29 @@ +rules: + - id: codevigilant.java.jenkins.credentials.lookup-null-authentication + patterns: + - pattern-either: + - pattern: CredentialsProvider.lookupCredentials($TYPE, $CTX, null) + - pattern: CredentialsProvider.lookupCredentials($TYPE, $CTX, null, $EXTRA) + - pattern: com.cloudbees.plugins.credentials.CredentialsProvider.lookupCredentials($TYPE, $CTX, null) + - pattern: com.cloudbees.plugins.credentials.CredentialsProvider.lookupCredentials($TYPE, $CTX, null, $EXTRA) + message: | + Detected CredentialsProvider.lookupCredentials invoked with a null + authentication argument. In the Credentials plugin, a null Authentication + is treated as ACL.SYSTEM, so the lookup returns credentials the current + user and current item may not be allowed to use. Resolve credentials with + the caller's authentication and the owning Item/ItemGroup, e.g. + CredentialsProvider.findCredentialById(id, type, item). + metadata: + category: security + cwe: "CWE-522: Insufficiently Protected Credentials" + owasp: "A01:2021 - Broken Access Control" + technology: jenkins + confidence: HIGH + references: + - https://www.jenkins.io/doc/developer/security/ + - https://javadoc.jenkins.io/plugin/credentials/com/cloudbees/plugins/credentials/CredentialsProvider.html + source: independent security review + license: MIT + languages: [java] + mode: search + severity: HIGH