CVE-2018-1000600
published 2018-06-26CVE-2018-1000600: A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows…
high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
ITWEXPLOIT
Exploited in the wild
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | aws_codebuild_plugin | — | — |
| jenkins | aws_codedeploy_plugin | — | — |
| jenkins | aws_codepipeline_plugin | — | — |
| jenkins | badge_plugin | — | — |
| jenkins | collabnet_plugin | — | — |
| jenkins | collabnet_plugins_plugin | — | — |
| jenkins | configuration_as_code_plugin | — | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | fortify_cloudscan_plugin | — | — |
| jenkins | github | <= 1.29.1 | — |
| jenkins | openstack_cloud_plugin | — | — |
| jenkins | os_connector_plugin | — | — |
| jenkins | saml_plugin | — | — |
| jenkins | ssh_credentials_plugin | — | — |
| jenkins | this_feature_applies_to_connections_by_this_plugin | — | — |
| jenkins | urltrigger_plugin | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck8.8HIGH