| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:nomad | maven |
| <= 0.7.4 |
| 0.7.5 |
The vulnerability stemmed from two key aspects:
The pre-patch version lacked Jenkins' Secret encryption mechanism for credential handling, making these functions directly responsible for the plaintext storage vulnerability. The commit diff confirms the security fix involved migrating to Secret type for password storage/retrieval.
KEV Misses 88% of Exploited CVEs- Get the report