-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the pre-patch implementation of fitsSearchBuildVariables() which processed all build variables without considering sensitivity. The commit diff shows the vulnerability was fixed by adding a check against sensitiveBuildVariables before evaluating values. The original code's loop over buildVariables.values() without sensitivity filtering directly matches the described attack vector where sensitive parameters could be discovered through search pattern matching.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.main:jenkins-core | maven | >= 2.50, < 2.414.2 | 2.414.2 |
| org.jenkins-ci.main:jenkins-core | maven | >= 2.415, < 2.424 | 2.424 |
Ongoing coverage of React2Shell