-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from plaintext credential storage in hudson.plugins.jira.JiraProjectProperty.xml. The commit e252f40 shows: 1) Deprecation of plaintext password fields with security warnings (CWE-256), 2) Introduction of Secret.encryptedPassword field, 3) Migration logic in readResolve() to move plaintext passwords to encrypted storage. The getPassword() and setPassword() methods directly handled plaintext credentials before encryption was implemented, making them the vulnerable entry points.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:jira-ext | maven | < 0.9 | 0.9 |
Ongoing coverage of React2Shell