-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from unencrypted storage of credentials in config.xml files. Jenkins plugin configuration is typically handled by Descriptor/Notifier classes that serialize data to XML. The functions responsible for persisting/retrieving the secret key would be in the plugin's core notifier class. The absence of encryption in these storage/retrieval functions matches the CWE-522 pattern described. While exact implementation details aren't available, this matches Jenkins plugin architecture patterns and the advisory's technical description of plaintext storage in job configs.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:azure-event-grid-notifier | maven | <= 0.1 |
KEV Misses 88% of Exploited CVEs- Get the report