CVE-2018-1000418

Description

An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.214

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in HipChat 2.2.0Windows
Vulnerabilities CVE-2018-1000418,CVE-2018-1000419 are fixed in Jvnet - hipchat 2.2.1Windows
Multiple vulnerabilities affected in HipChat 2.2.0 (For Ubuntu)Linux
Multiple vulnerabilities affected in HipChat 2.2.0 (For Debian)Linux
Multiple vulnerabilities affected in HipChat 2.2.0 (For Centos)Linux
Multiple vulnerabilities affected in HipChat 2.2.0 (For RedHat)Linux
Multiple vulnerabilities affected in HipChat 2.2.0 (For Suse)Linux
Vulnerabilities CVE-2018-1000418,CVE-2018-1000419 are fixed in Jvnet - hipchat for Linux 2.2.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234