cbcvebase.
CVE-2018-1000143
published 2018-04-05

CVE-2018-1000143: An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows…

medium6.7CVSS 3.0
AVLACLPRHUINSUCHIHAH
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials.

Affected

12 ranges
VendorProductVersion rangeFixed in
jenkinsansible_plugin
jenkinsbuilds_started_before_the_plugin
jenkinscopy_to_slave_plugin
jenkinscucumber_living_documentation_plugin
jenkinsgithub_pull_request_builder<= 1.39.0
jenkinsgithub_pull_request_builder_plugin
jenkinsliquibase_runner_plugin
jenkinsmailer_plugin
jenkinsp4_plugin
jenkinsperforce_plugin
jenkinsreverse_proxy_auth_plugin
jenkinswe_recommend_that_users_of_perforce_plugin