CVE-2018-1000109

MEDIUM

Jenkins Google Play Android Publisher Plugin <1.6 - Auth Bypass

Title source: llm
STIX 2.1

Description

An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 9.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-863
Status published
Products (2)
jenkins/google-play-android-publisher < 1.6
org.jenkins-ci.plugins/google-play-android-publisher 0 - 1.7Maven
Published Mar 13, 2018
Tracked Since Feb 18, 2026