PT-2018-15215 · Jenkins · Jenkins Ssh Agent Plugin+1
Jan Hollevoet
·
Publicado
2018-08-01
·
Atualizado
2022-05-13
·
CVE-2018-1999036
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins SSH Agent Plugin versions 1.15 and earlier
Description
An exposure of sensitive information issue exists in the Jenkins SSH Agent Plugin that exposes the SSH private key password to users with permission to read the build log. This occurs due to the logging of the ssh-add invocation in the SSHAgentStepExecution.java file, which reveals the passphrase.
Recommendations
For Jenkins SSH Agent Plugin versions 1.15 and earlier, update to version 1.16 or later, as it no longer logs the ssh-add invocation that would reveal the passphrase.
Correção
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jenkins
Jenkins Ssh Agent Plugin