-
CVSS Score
-The vulnerability stems from an unauthenticated webhook endpoint at /quayio-webhook/. In Jenkins plugin architecture:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:quayio-trigger | maven | <= 0.1 |
Ongoing coverage of React2Shell