-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from storing credentials as plaintext Strings in Jenkins job configurations. The commit diff shows password fields were originally declared as String types and later replaced with Jenkins' Secret type across multiple builder classes (BuildBuilder, ServerAuth, SyncBuilder, TestBuilder). The getPassword() methods directly exposed these credentials in config.xml files. The fix involved encrypting credentials using Jenkins' credential management system, confirming these functions were the vulnerable points.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.redgate.plugins.redgatesqlci:redgate-sql-ci | maven | < 2.0.4 | 2.0.4 |
Ongoing coverage of React2Shell