-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| ru.yandex.jenkins.plugins.debuilder:debian-package-builder | maven | <= 1.6.11 |
The vulnerability stems from unencrypted storage of credentials in Jenkins' XML configuration files. In Jenkins plugin architecture:
Though no patch is available, the pattern matches Jenkins' configuration handling: