Improper Authorization in Jenkins HipChat Plugin from CloudBees
CVE-2018-1000418
8.8HIGH
What is CVE-2018-1000418?
The Jenkins HipChat Plugin contains a vulnerability that allows users with Overall/Read access to send test notifications to any HipChat server with arbitrary credentials. This occurs due to a flaw in the HipChatNotifier.java file, enabling attackers to exploit this vulnerability to capture stored credentials from Jenkins. This could potentially lead to unauthorized access and compromise sensitive data.