-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from plaintext password storage in ZeeReporter.xml. Jenkins plugins typically:
While no patch code is available, the advisory explicitly identifies:
These functions would appear in runtime profiling when:
High confidence in getPassword() as it directly exposes the sensitive value. Medium confidence in descriptor save mechanism as it's pattern-based inference.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:zephyr-enterprise-test-management | maven | < 1.10 | 1.10 |
KEV Misses 88% of Exploited CVEs- Get the report