GHSA-cg6q-gp23-vwx8
HIGHCVE-2018-1000423An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.
- Affected
- <= 2.0.0
- Fixed in
- 2.0.1
- Published
- 2022-05-13
- Source
- github