-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:harvest | maven | <= 0.5.1 |
The vulnerability stems from unencrypted password storage in XML configuration files. Jenkins plugins typically serialize configuration data using XStream, and the HarvestSCM class's password field would be directly serialized. The DescriptorImpl.configure() method would handle global configuration persistence. Both locations fail to use Jenkins' Secret class or equivalent encryption mechanisms before storage, violating credential protection best practices. The advisory explicitly identifies these two storage locations (global config and job config.xml), which map directly to these functions.
Ongoing coverage of React2Shell