-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:sonar-gerrit | maven | < 2.4.5 | 2.4.5 |
The vulnerability stemmed from handling passwords as plain text strings rather than encrypted Secrets. Key indicators:
Ongoing coverage of React2Shell