VYPR

Eiffel Broadcaster

by Jenkins Project

CVEs (1)

  • CVE-2025-24400MedJan 22, 2025
    risk 0.00cvss 4.3epss 0.00

    Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event…