CVE-2018-1999034: Jenkins Inedo Proget
High severity, CVSS 7.4. EPSS: 0.8% chance of exploitation in the next 30 days.
A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.java that allows attackers to impersonate any service that Jenkins connects to.
Affected products
- Jenkins Inedo Proget: up to and including 0.8
Published 2018-08-01. Last modified 2026-06-17.