PT-2018-9455 · Jenkins · Jenkins Git Plugin+1

Orange Tsai

+1

·

Published

2018-06-26

·

Updated

2022-05-13

·

CVE-2018-1000600

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins GitHub Plugin versions 1.29.1 and earlier
Description A sensitive information exposure issue exists, allowing attackers to capture credentials stored in Jenkins by using attacker-specified credentials IDs obtained through another method to access an attacker-specified URL.
Recommendations For Jenkins GitHub Plugin versions 1.29.1 and earlier, consider restricting access to the GitHubTokenCredentialsCreator.java file until a patch is available. As a temporary workaround, avoid using the credentials IDs in the affected plugin to minimize the risk of exploitation.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000600
GHSA-6CVM-V6QJ-HJQ9

Affected Products

Jenkins
Jenkins Git Plugin