-
CVSS Score
-The vulnerability stems from plaintext storage of credentials in configuration files. The SSHUserPrivateKey and SSHUserInfo classes would contain methods exposing these credentials. The descriptor's load() method would handle loading the vulnerable configuration. While exact patch details aren't available, the advisory explicitly calls out these credential types as being stored insecurely, and the migration to Credentials Plugin indicates these were the legacy storage mechanisms.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jvnet.hudson.plugins:ssh | maven | <= 2.3 | |
| org.jenkins-ci.plugins:ssh | maven | < 2.5 | 2.5 |
Ongoing coverage of React2Shell