CVE-2018-1000423 describes an insufficiently protected credentials vulnerability in Jenkins Crowd 2 Integration Plugin versions 2.0.0 and earlier. This flaw allows an attacker with local file system access to retrieve credentials used to connect to Crowd 2. Rated with a CVSS score of 7.8 (HIGH), this vulnerability has a local attack vector and low attack complexity, enabling high impact on confidentiality, integrity, and availability. It is classified as CWE-522 (Insufficiently Protected Credentials). Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.0CPE matchmatch criteria | cpe:2.3:a:atlassian:crowd2:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.