| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:google-compute-engine | maven |
| <= 4.1.1 |
| 4.2.0 |
The vulnerability stems from missing SSH host key verification when connecting to agents. Analysis of Jenkins plugin patterns indicates:
KEV Misses 88% of Exploited CVEs- Get the report