A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.
https://github.com/advisories/GHSA-75fc-fv3p-xh82
https://www.jenkins.io/security/advisory/2022-07-27/#SECURITY-2621