Vulnerabilities
Vulnerable Software
Atlassian:  >> Crowd2  >> 1.3  Security Vulnerabilities
An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server with attacker-specified credentials and connection settings.
CVSS Score
6.5
EPSS Score
0.001
Published
2019-01-09
An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.
CVSS Score
7.8
EPSS Score
0.0
Published
2019-01-09


Contact Us

Shodan ® - All rights reserved