-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from improper credential handling in two key areas: 1) The descriptor's configure method persists configuration data without encrypting the password field. 2) The password field is stored/retrieved as plaintext rather than using Jenkins' secure credential storage mechanisms (Secret class). This matches Jenkins plugin vulnerability patterns where sensitive fields aren't properly marked as @DataBoundConstructor parameters with Secret serialization.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:elasticsearch-query | maven | <= 1.2 |
Ongoing coverage of React2Shell