CVE-2018-1000147: Infoleak
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with insufficient permission to obtain Perforce passwords configured in jobs to obtain them
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1000147?
CVE-2018-1000147 is an exposure of sensitive information vulnerability in Jenkins Perforce Plugin version 1.3.36 and older.
What is the severity of CVE-2018-1000147?
The severity of CVE-2018-1000147 is medium with a CVSS score of 6.5.
How does CVE-2018-1000147 affect Perforce Plugin?
CVE-2018-1000147 affects Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java.
How can attackers exploit CVE-2018-1000147?
Attackers with insufficient permission can exploit CVE-2018-1000147 to obtain Perforce passwords configured in jobs.
Is there a fix available for CVE-2018-1000147?
Yes, it is recommended to update to a newer version of Jenkins Perforce Plugin that addresses the vulnerability.