ZeroHour

CVE-2018-1999030

CVSS 3.0
5.4 medium
EPSS
<1%p50
Published
()
Modified
Description

An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and earlier in ArtifactoryChoiceListProvider.java, NexusChoiceListProvider.java, Nexus3ChoiceListProvider.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.

Vendors
jenkins
Products
maven artifact choicelistprovider \(nexus\)
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.