-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability explicitly states credentials are stored unencrypted in job config.xml files. In Jenkins plugin architecture, credential handling typically involves functions that serialize/deserialize configuration data. The functions above are inferred based on standard Jenkins plugin patterns:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:eggplant-plugin | maven | <= 2.2 |
KEV Misses 88% of Exploited CVEs- Get the report