-
CVSS Score
-The vulnerability explicitly states credentials are stored unencrypted in KojiBuilder.xml. In Jenkins plugin architecture, the configure() method typically handles configuration data persistence. Since the credentials are stored in plain text, the function responsible for serializing configuration data (likely configure() in KojiBuilder class) fails to use Jenkins' credential encryption mechanisms.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:koji | maven | <= 0.3 |
A Semantic Attack on Google Gemini - Read the Latest Research