CVE-2018-1000422: Atlassian CROWD2

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server with attacker-specified credentials and connection settings.

Affected products

Published 2019-01-09. Last modified 2026-06-17.