CVE-2018-1000600
published 2018-06-26CVE-2018-1000600: A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows…
PriorityP183high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
90.89%
99.8th percentile
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | aws_codebuild_plugin | — | — |
| jenkins | aws_codedeploy_plugin | — | — |
| jenkins | aws_codepipeline_plugin | — | — |
| jenkins | badge_plugin | — | — |
| jenkins | collabnet_plugin | — | — |
| jenkins | collabnet_plugins_plugin | — | — |
| jenkins | configuration_as_code_plugin | — | — |
| jenkins | credentials_binding_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | fortify_cloudscan_plugin | — | — |
| jenkins | github | <= 1.29.1 | — |
| jenkins | openstack_cloud_plugin | — | — |
| jenkins | os_connector_plugin | — | — |
| jenkins | saml_plugin | — | — |
| jenkins | ssh_credentials_plugin | — | — |
| jenkins | this_feature_applies_to_connections_by_this_plugin | — | — |
| jenkins | urltrigger_plugin | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/securityRealm/user/admin/descriptorByName/org.jenkinsci.plugins.github.config.GitHubTokenCredentialsCreator/createTokenByPassword?apiUrl=http://{{interactsh-url}}↗
path/securityRealm/user/admin/descriptorByName/org.jenkinsci.plugins.github.config.GitHubTokenCredentialsCreator/createTokenByPassword↗
- →Detect unauthenticated or low-privilege GET requests to the GitHubTokenCredentialsCreator createTokenByPassword endpoint with an external apiUrl parameter — indicates SSRF exploitation attempt. ↗
- →Flag GET (non-POST) requests to the createTokenByPassword form action endpoint; the vulnerability is exploitable via GET due to missing CSRF (POST) enforcement. ↗
- →Alert on requests to the Jenkins GitHub Plugin credential-creation endpoint by users with only Overall/Read access — the endpoint does not enforce permission checks. ↗
- →Confirm exploitation by observing an outbound HTTP callback (OOB interaction) from the Jenkins server to an attacker-controlled host triggered via the apiUrl parameter. ↗
- ·The SSRF endpoint requires the attacker to supply a credentials ID obtained through a separate method; the vulnerability alone does not expose credential IDs — a chained attack is needed. ↗
- ·Affected versions are Jenkins GitHub Plugin 1.29.1 and earlier; version 1.29.2+ is not vulnerable. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vulncheck8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials
ghsa·2022-05-13
CVE-2018-1000600 [HIGH] CWE-200 CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials
CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
OSV
CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials
osv·2022-05-13
CVE-2018-1000600 [HIGH] CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials
CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
VulnCheck
Jenkins github Exposure of Sensitive Information to an Unauthorized Actor
vulncheck·2018·CVSS 8.8
CVE-2018-1000600 [HIGH] Jenkins github Exposure of Sensitive Information to an Unauthorized Actor
Jenkins github Exposure of Sensitive Information to an Unauthorized Actor
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected: Jenkins github
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.f5.com/labs/articles/threat-intelligence/sensor-intel-series-top-cves-august-2024; https://www.f5.com/labs/articles/threat-intelligence/botpoke-scanner-switches-ip; https://www.f5.com/labs/articles/t
Jenkins
Jenkins Security Advisory 2018-06-25
vendor_jenkins·2018-06-25·CVSS 8.8
CVE-2018-1000401 [HIGH] Jenkins Security Advisory 2018-06-25
Title: Jenkins Security Advisory 2018-06-25
Jenkins Security Advisory 2018-06-25
Jenkins Security Home
For Administrators
Overview
Terminology
Vulnerabilities and Scoring
Security Advisories
Security Issues
Advisory Schedule
Vulnerabilities in Plugins
How We Fix Security Issues
For Reporters
Reporting Vulnerabilities
Jenkins CNA
For Maintainers
Overview
Vulnerabilities in Plugins
Jenkins Security Team
About
Contributions
This advisory announces vulnerabilities in the following Jenkins deliverables:
AWS CodeBuild
Plugin
AWS CodeDeploy
Plugin
AWS CodePipeline
Plugin
Badge
Plugin
CollabNet Plugins
Plugin
Configuration as Code
Plugin
fortify-cloudscan-jenkins-plugi
Red Hat
jenkins-plugin-github: CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials (SECURITY-915)
vendor_redhat·2018-06-25·CVSS 8.8
CVE-2018-1000600 [HIGH] CWE-352 jenkins-plugin-github: CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials (SECURITY-915)
jenkins-plugin-github: CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials (SECURITY-915)
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Package: jenkins-plugin-github (Red Hat OpenShift Enterprise 3) - Affected
No detection rules found.
Nuclei
Jenkins GitHub Plugin <=1.29.1 - Server-Side Request Forgery
nuclei·CVSS 8.8
CVE-2018-1000600 [HIGH] Jenkins GitHub Plugin <=1.29.1 - Server-Side Request Forgery
Jenkins GitHub Plugin <=1.29.1 - Server-Side Request Forgery
Jenkins GitHub Plugin 1.29.1 and earlier is susceptible to server-side request forgery via GitHubTokenCredentialsCreator.java, which allows attackers to leverage attacker-specified credentials IDs obtained through another method and capture the credentials stored in Jenkins.
Template:
id: CVE-2018-1000600
info:
name: Jenkins GitHub Plugin <=1.29.1 - Server-Side Request Forgery
author: geeknik
severity: high
description: |
Jenkins GitHub Plugin 1.29.1 and earlier is susceptible to server-side request forgery via GitHubTokenCredentialsCreator.java, which allows attackers to leverage attacker-specified credentials IDs obtained through another method and capture the credentials stored in Jenkins.
impact: |
Successful exploitation
Unit42
Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious Purposes
blogs_unit42·2021-10-14
Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious Purposes
## Executive Summary
Recently, Unit 42 has observed active exploits related to an open-source service called Interactsh. This tool can generate specific domain names to help its users test whether an exploit is successful. It can be used by researchers – but also by attackers – to validate vulnerabilities via real-time monitoring on the trace path for the domain. Researchers creating a proof of concept (PoC) for an exploit can insert Interactsh to check whether the PoC is working, but the service could also be used by attackers who want to be sure an exploit is working.
This blog will first introduce the Interactsh tool and how researchers or attackers can leverage it to perform vulnerability validation. We then describe some of the many exploits in the wild leveraging this tool, and we
Unit42
Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious Purposes
blogs_unit42·2021-10-14
Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious Purposes
Threat Research Center
Threat Research
Cybercrime
## Attackers Are Taking Advantage of the Open-Source Service Interactsh for Malicious Purposes
Yue Guan
Jin Chen
Leo Olson
Wayne Xin
Daiping Liu
Published: October 14, 2021
Cybercrime
Threat Research
Attack analysis
Exploit
Exploit in the wild
Interactsh
## Executive Summary
Recently, Unit 42 has observed active exploits related to an open-source service called Interactsh . This tool can generate specific domain names to help its users test whether an exploit is successful. It can be used by researchers – but also by attackers – to validate vulnerabilities via real-time monitoring on the trace path for the domain. Researchers creating a proof of concept (PoC) for an exploit can insert Interactsh to check whether the PoC
Greynoiseio
NoiseLetter October 2025
blogs_greynoiseio
NoiseLetter October 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Bugzilla
CVE-2018-1000600 jenkins-plugin-github: CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials (SECURITY-915)
bugzilla·2018-06-28·CVSS 8.8
CVE-2018-1000600 [HIGH] CVE-2018-1000600 jenkins-plugin-github: CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials (SECURITY-915)
CVE-2018-1000600 jenkins-plugin-github: CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials (SECURITY-915)
A form action method in GitHub Plugin did not check the permission of the user accessing it, allowing anyone with Overall/Read access to Jenkins to cause Jenkins to send a GitHub API request to create an API token to an attacker-specified URL.
This allowed users with Overall/Read access to Jenkins to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Additionally, this form validation method did not require POST requests, resulting in a CSRF vulnerability.
External References:
https://jenkins.io/security/advisory/2018-06-25/
2018-06-26
Published
Exploited in the wild