First published: Thu Apr 05 2018(Updated: )
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with insufficient permission to obtain Perforce passwords configured in jobs to obtain them
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Perforce Perforce | <=1.3.36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000147 is an exposure of sensitive information vulnerability in Jenkins Perforce Plugin version 1.3.36 and older.
The severity of CVE-2018-1000147 is medium with a CVSS score of 6.5.
CVE-2018-1000147 affects Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java.
Attackers with insufficient permission can exploit CVE-2018-1000147 to obtain Perforce passwords configured in jobs.
Yes, it is recommended to update to a newer version of Jenkins Perforce Plugin that addresses the vulnerability.