Insufficiently Protected Credentials in Jenkins Crowd 2 Integration Plugin
CVE-2018-1000423
7.8HIGH
What is CVE-2018-1000423?
A flaw in the Jenkins Crowd 2 Integration Plugin allows attackers with local file system access to retrieve sensitive credentials utilized for connecting to Crowd 2. This vulnerability resides in the CrowdSecurityRealm.java and CrowdConfigurationService.java files, emphasizing the need for enhanced security measures to protect sensitive data effectively.