CVE-2018-1000109: Jenkins Google-Play-Android-Publisher

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs.

Affected products

  • Jenkins Google-Play-Android-Publisher: up to and including 1.6

Published 2018-03-13. Last modified 2026-06-17.