-
CVSS Score
-The vulnerability stemmed from handling credentials as plain text Strings rather than Jenkins' Secret type. Key evidence comes from the patch diff showing:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| hudson.plugins.klaros:klaros-testmanagement | maven | <= 2.0.0 | 2.1.0 |