CVE-2018-1000112: Jenkins Mercurial
Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.
An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.
Affected products
- Jenkins Mercurial: up to and including 2.2
Published 2018-03-13. Last modified 2026-06-17.