-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.mobileenerlytics.eagle.tester:eagle-tester | maven | <= 1.0.9 |
The vulnerability stems from unencrypted password storage in the global configuration file. Jenkins plugins typically use a configure() method in their Descriptor/configuration classes to persist settings. The advisory explicitly references the RPDPluginConfiguration.xml file path, indicating the RPDPluginConfiguration class is responsible for credential storage. Since no encryption is applied during configuration serialization (as confirmed by the plaintext storage description), the method handling configuration persistence (likely configure() or related XML serialization) is the root cause.
Ongoing coverage of React2Shell