-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:elastest | maven | <= 1.2.1 |
The vulnerability explicitly involves unencrypted password storage in ElasTestInstallation.xml. Jenkins plugins typically use setters/getters (like setServerPassword/getServerPassword) to manage configuration properties. The absence of encryption in these functions directly enables cleartext storage. While specific code isn't shown, the pattern matches Jenkins plugin security anti-patterns for credential storage, and the advisory explicitly identifies the configuration file and storage mechanism.
Ongoing coverage of React2Shell