-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The commit diff shows these functions were modified to return Secret objects instead of decrypted strings. Previously, they used Secret.toString() to return plaintext credentials, which were transmitted unencrypted in configuration forms. The vulnerability stemmed from exposing decrypted secrets through these accessors during form submission.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:backlog | maven | < 2.5 | 2.5 |
KEV Misses 88% of Exploited CVEs- Get the report