cbcvebase.
CVE-2018-1000187
published 2018-06-05

CVE-2018-1000187: A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive…

medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive variables such as passwords being written to logs.

Affected

11 ranges
VendorProductVersion rangeFixed in
jenkinsabsint_astre_plugin
jenkinsblack_duck_detect_plugin
jenkinsblack_duck_hub_plugin
jenkinscas_plugin
jenkinsgit_plugin
jenkinsgithub_branch_source_plugin
jenkinsgithub_plugin
jenkinsgithub_pull_request_builder_plugin
jenkinskubernetes<= 1.7.0
jenkinskubernetes_plugin
jenkinsvarious_form_validation_methods_in_git_plugin