VYPR

Maven Artifact Choicelistprovider \(nexus\)

by Jenkins Project

Source repositories

CVEs (2)

  • CVE-2023-40347MedAug 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

  • CVE-2018-1999030MedAug 1, 2018
    risk 0.28cvss 5.4epss 0.01

    An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and earlier in ArtifactoryChoiceListProvider.java, NexusChoiceListProvider.java, Nexus3ChoiceListProvider.java that allows attackers to capture credentials…