CVE-2017-1000245

Severity
9.8CRITICAL
EPSS
0.1%
top 80.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 1
Latest updateMay 13

Description

The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

3
OSV
Jenkins SSH Plugin user passwords for encrypted SSH keys stored in plaintext2022-05-13
GHSA
Jenkins SSH Plugin user passwords for encrypted SSH keys stored in plaintext2022-05-13
CVEList
CVE-2017-1000245: The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol2017-11-01

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2017-07-102017-07-10
CVE-2017-1000245 (CRITICAL CVSS 9.8) | The SSH Plugin stores credentials w | cvebase.io