Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier uses static fields to store job configuration information, allowing attackers with Item/Configure permission to capture passwords of the jobs that will be configured.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.convertigo.jenkins.plugins:convertigo-mobile-platform(Maven) | 0 | N/A | N/A |
CVSS Metrics