{"api_version":"1","generated_at":"2026-07-23T09:38:47+00:00","cve":"CVE-2018-1000145","urls":{"html":"https://cve.report/CVE-2018-1000145","api":"https://cve.report/api/cve/CVE-2018-1000145.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-1000145","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000145"},"summary":{"title":"CVE-2018-1000145","description":"An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with local file system access to obtain encrypted Perforce passwords and decrypt them.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-04-05 13:29:00","updated_at":"2019-10-03 00:03:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://jenkins.io/security/advisory/2018-03-26/#SECURITY-373","name":"https://jenkins.io/security/advisory/2018-03-26/#SECURITY-373","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Jenkins Security Advisory 2018-03-26","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-1000145","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000145","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"1000145","vulnerable":"1","versionEndIncluding":"1.3.36","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jenkins","cpe5":"perforce","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"jenkins","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2018-1000145","qid":"997307","title":"Java (Maven) Security Update for org.jvnet.hudson.plugins:perforce (GHSA-cwxx-gwwj-pqjq)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-1000145","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with local file system access to obtain encrypted Perforce passwords and decrypt them."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://jenkins.io/security/advisory/2018-03-26/#SECURITY-373","refsource":"CONFIRM","url":"https://jenkins.io/security/advisory/2018-03-26/#SECURITY-373"}]}},"nvd":{"publishedDate":"2018-04-05 13:29:00","lastModifiedDate":"2019-10-03 00:03:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:jenkins:perforce:*:*:*:*:*:jenkins:*:*","versionEndIncluding":"1.3.36","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"1000145","Ordinal":"125712","Title":"CVE-2018-1000145","CVE":"CVE-2018-1000145","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"1000145","Ordinal":"1","NoteData":"An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with local file system access to obtain encrypted Perforce passwords and decrypt them.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"1000145","Ordinal":"2","NoteData":"2018-04-05","Type":"Other","Title":"Published"}]}}}