-
CVSS Score
-The vulnerability stemmed from credentials being stored unencrypted in the global config XML file. Key evidence from the commit diff shows:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:bumblebee | maven | <= 4.1.5 | 4.1.6 |