cbcvebase.
CVE-2018-1000187
published 2018-06-05

CVE-2018-1000187: A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive…

PriorityP431medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.27%
66.4th percentile
A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive variables such as passwords being written to logs.

Affected

11 ranges
VendorProductVersion rangeFixed in
jenkinsabsint_astre_plugin
jenkinsblack_duck_detect_plugin
jenkinsblack_duck_hub_plugin
jenkinscas_plugin
jenkinsgit_plugin
jenkinsgithub_branch_source_plugin
jenkinsgithub_plugin
jenkinsgithub_pull_request_builder_plugin
jenkinskubernetes<= 1.7.0
jenkinskubernetes_plugin
jenkinsvarious_form_validation_methods_in_git_plugin

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.