CVE-2018-1000423: Atlassian CROWD2

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.

Affected products

Published 2019-01-09. Last modified 2026-06-17.