cbcvebase.
CVE-2018-1999040
published 2018-08-01

CVE-2018-1999040: An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to…

PriorityP342high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.40%
69.3th percentile
An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.

Affected

17 ranges
VendorProductVersion rangeFixed in
jenkinsaccurev_plugin
jenkinsagiletestware_pangolin_connector_for_testrail_plugin
jenkinsanchore_container_image_scanner_plugin
jenkinsconfluence_publisher_plugin
jenkinscredentials_plugin
jenkinsinedo_buildmaster_plugin
jenkinsinedo_proget_plugin
jenkinskubernetes<= 1.10.1
jenkinskubernetes_plugin
jenkinspublish_over_cifs_plugin
jenkinsread_access_to_jenkins_to_override_the_plugin
jenkinsresource_disposer_plugin
jenkinssaltstack_plugin
jenkinsshelve_project_plugin
jenkinsssh_agent_plugin
jenkinstinfoil_security_plugin
jenkinstracetronic_ecu-test_plugin

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.