GHSA-cg6q-gp23-vwx8
Dashboard / Vulnerabilities / GHSA-cg6q-gp23-vwx8
Summary: Jenkins Crowd 2 Integration Plugin stored credentials in plain text
Details: An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-1000423, https://github.com/jenkinsci/crowd2-plugin/commit/580be2a0dfb38d494420901f03555092b885a85f, https://github.com/jenkinsci/crowd2-plugin, https://jenkins.io/security/advisory/2018-09-25/#SECURITY-1068, http://www.securityfocus.com/bid/106532
Affected packages
Package
Name: org.jenkins-ci.plugins:crowd2
Purl: pkg:maven/org.jenkins-ci.plugins/crowd2
Affected ranges
Type: ECOSYSTEM
Events:
