CVE-2018-1000419

Description

An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.259

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in HipChat 2.2.0Windows
Vulnerabilities CVE-2018-1000418,CVE-2018-1000419 are fixed in Jvnet - hipchat 2.2.1Windows
Multiple vulnerabilities affected in HipChat 2.2.0 (For Ubuntu)Linux
Multiple vulnerabilities affected in HipChat 2.2.0 (For Debian)Linux
Multiple vulnerabilities affected in HipChat 2.2.0 (For Centos)Linux
Multiple vulnerabilities affected in HipChat 2.2.0 (For RedHat)Linux
Multiple vulnerabilities affected in HipChat 2.2.0 (For Suse)Linux
Vulnerabilities CVE-2018-1000418,CVE-2018-1000419 are fixed in Jvnet - hipchat for Linux 2.2.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234