5
CVSSv2

CVE-2018-1000112

Published: 13/03/2018 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and previous versions in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins mercurial

Vendor Advisories

An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 22 and earlier in MercurialStatusjava that allows an attacker with network access to obtain a list of nodes and users ...