QID 996900

Date Published: 2024-01-29

QID 996900: Java (Maven) Security Update for org.jenkins-ci.plugins:crowd2 (GHSA-cg6q-gp23-vwx8)

An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Refer to Github security advisory GHSA-cg6q-gp23-vwx8 for updates and patch information.
    Vendor References

    CVEs related to QID 996900

    Software Advisories
    Advisory ID Software Component Link
    GHSA-cg6q-gp23-vwx8 org.jenkins-ci.plugins:crowd2 URL Logo github.com/advisories/GHSA-cg6q-gp23-vwx8