First published: Wed Aug 01 2018(Updated: )
An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and earlier in ArtifactoryChoiceListProvider.java, NexusChoiceListProvider.java, Nexus3ChoiceListProvider.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Maven Artifact Choicelistprovider \(nexus\) | <=1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1999030 is classified as a high severity vulnerability.
To fix CVE-2018-1999030, upgrade the Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin to version 1.3.2 or later.
CVE-2018-1999030 affects users of Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin versions 1.3.1 and earlier.
CVE-2018-1999030 is an exposure of sensitive information vulnerability.
The potential impacts of CVE-2018-1999030 include the capture of sensitive credentials by attackers.