-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.moded.extendedchoiceparameter:dynamic_extended_choice_parameter | maven | <= 1.0.1 |
The vulnerability stems from unencrypted storage of credentials in config.xml files. Jenkins parameter plugins typically implement ParameterDefinition classes with configure() for handling inputs and toXML() for serialization. The advisory specifically mentions Subversion password storage, indicating these functions failed to use Jenkins' credential storage mechanisms or encryption when persisting sensitive data to job configurations.
KEV Misses 88% of Exploited CVEs- Get the report