QID 996905
Date Published: 2024-01-29
QID 996905: Java (Maven) Security Update for org.jenkins-ci.plugins:crowd2 (GHSA-grmg-5q49-mqmf)
An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server with attacker-specified credentials and connection settings.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-grmg-5q49-mqmf for updates and patch information.
Vendor References
- GHSA-grmg-5q49-mqmf -
github.com/advisories/GHSA-grmg-5q49-mqmf
CVEs related to QID 996905
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-grmg-5q49-mqmf | org.jenkins-ci.plugins:crowd2 |
|