CVE-2018-1000147

MEDIUM6.5EPSS 0.29%

Jenkins Perforce Plugin exposure of sensitive information vulnerability exists

Published: 5/14/2022Modified: 2/16/2024

Description

An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with insufficient permission to obtain Perforce passwords configured in jobs to obtain them

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

References (2)