-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:repository-connector | maven | <= 1.2.6 | 2.0.0 |
The vulnerability stems from credentials being transmitted in plaintext during configuration form submission. Jenkins plugins typically handle configuration via a configure method in their descriptor/configuration class. The advisory explicitly states credentials are stored encrypted on disk but transmitted in plaintext, indicating the form-handling code (like RepositoryConfiguration.configure()) processes raw credentials without secure transmission mechanisms. This matches Jenkins plugin architecture patterns where form data binding occurs in such methods.
Ongoing coverage of React2Shell