-
CVSS Score
-The vulnerability stems from the plugin's implementation of credential storage. Jenkins plugins should use the credentials API (CredentialsProvider) for secure storage, but this plugin instead directly serializes sensitive values to job config.xml. The key indicators are:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:crittercism-dsym | maven | <= 1.1 |