CVE-2018-1000422: Atlassian CROWD2
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server with attacker-specified credentials and connection settings.
Affected products
- Atlassian CROWD2: up to and including 2.0.0
Published 2019-01-09. Last modified 2026-06-17.