CVE-2018-1000412: High severity jenkins vulnerability
An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1000412?
CVE-2018-1000412 is an improper authorization vulnerability in Jenkins Jira Plugin.
What is the severity of CVE-2018-1000412?
The severity of CVE-2018-1000412 is high with a score of 8.8.
How does CVE-2018-1000412 affect software?
CVE-2018-1000412 affects Jenkins Jira Plugin versions up to 3.0.1.
How can the vulnerability be exploited?
Attackers with Overall/Read access can use Jenkins to connect to a specified URL with attacker-specified credentials obtained through another method.
Where can I find more information about CVE-2018-1000412?
You can find more information about CVE-2018-1000412 in the references provided: http://www.securityfocus.com/bid/106532 and https://jenkins.io/security/advisory/2018-09-25/#SECURITY-1029.