CVE-2017-1000245: Jenkins SSH
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.
Affected products
- Jenkins SSH: up to and including 2.4
Published 2017-11-01. Last modified 2026-06-17.