cbcvebase.
CVE-2018-1000104
published 2018-03-13

CVE-2018-1000104: A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with local…

high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with local file system access or control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured keystore and private key passwords.

Affected

20 ranges
VendorProductVersion rangeFixed in
jenkinsazure_slave_plugin
jenkinsazure_vm_agents_plugin
jenkinscoverity<= 1.10.0
jenkinscoverity_plugin
jenkinscppncss_plugin
jenkinscredentials_plugin
jenkinsenvinject_plugin
jenkinsenvironment_injector_plugin
jenkinsgerrit_trigger_plugin
jenkinsgit_plugin
jenkinsgoogle_play_android_publisher_plugin
jenkinsids_in_google_play_android_publisher_plugin
jenkinsimproper_access_control_in_gerrit_trigger_plugin
jenkinsjob_and_node_ownership_plugin
jenkinsmercurial_plugin
jenkinstestlink_plugin
jenkinsurl_in_git_plugin
jenkinsurl_in_mercurial_plugin
jenkinsurl_in_subversion_plugin
jenkinsyou_have_ever_used_environment_injector_plugin