CVE-2018-1000425
Summary
| CVE | CVE-2018-1000425 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-09 23:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allows attackers with local file system access to obtain the credentials used to connect to SonarQube. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Jenkins Multiple Security Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Jenkins Security Advisory 2018-09-25 |
CONFIRM |
jenkins.io |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 997278 Java (Maven) Security Update for org.jenkins-ci.plugins:sonar (GHSA-3ccq-gccx-pm7j)