CVE-2018-1000423: Atlassian CROWD2
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.
Affected products
- Atlassian CROWD2: up to and including 2.0.0
Published 2019-01-09. Last modified 2026-06-17.