CVE-2018-1000423: High severity atlassian crowd vulnerability
An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000423?
CVE-2018-1000423 is rated as a medium severity vulnerability due to its ability to expose credentials.
How do I fix CVE-2018-1000423?
To fix CVE-2018-1000423, upgrade to a version of the Jenkins Crowd 2 Integration Plugin later than 2.0.0.
What is affected by CVE-2018-1000423?
CVE-2018-1000423 affects Jenkins Crowd 2 Integration Plugin version 2.0.0 and earlier.
What are the implications of CVE-2018-1000423?
The implications of CVE-2018-1000423 include potential unauthorized access to credentials used for connecting to Crowd 2.
Who is impacted by CVE-2018-1000423?
Organizations using the vulnerable versions of Jenkins Crowd 2 Integration Plugin are at risk due to CVE-2018-1000423.