An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.
2019-01-09T23:29:02.887
2024-11-21T03:40:02.663
Modified
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9