CVE-2018-1000610

CVSS v3.0 8.8 (High)
88% Progress
CVSS v2.0 4 (Medium)
40% Progress
EPSS 0.10 % (43th)
0.10% Progress
Affected Products 1
Advisories 2

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to Jenkins log files to obtain the passwords configured using Configuration as Code Plugin.

Weaknesses
CWE-522
Insufficiently Protected Credentials
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2018-06-26 17:29:00
(6 years ago)
Updated Date
2019-10-03 00:03:26
(5 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Configuration As Code 0.1 Alpha for Jenkins cpe:2.3:a:jenkins:configuration_as_code:0.1:alpha:*:*:*:jenkins
  Jenkins Configuration As Code 0.2 Alpha for Jenkins cpe:2.3:a:jenkins:configuration_as_code:0.2:alpha:*:*:*:jenkins
  Jenkins Configuration As Code 0.3 Alpha for Jenkins cpe:2.3:a:jenkins:configuration_as_code:0.3:alpha:*:*:*:jenkins
  Jenkins Configuration As Code 0.4 Alpha for Jenkins cpe:2.3:a:jenkins:configuration_as_code:0.4:alpha:*:*:*:jenkins
  Jenkins Configuration As Code 0.5 Alpha for Jenkins cpe:2.3:a:jenkins:configuration_as_code:0.5:alpha:*:*:*:jenkins
  Jenkins Configuration As Code 0.6 Alpha for Jenkins cpe:2.3:a:jenkins:configuration_as_code:0.6:alpha:*:*:*:jenkins
  Jenkins Configuration As Code 0.7 Alpha for Jenkins cpe:2.3:a:jenkins:configuration_as_code:0.7:alpha:*:*:*:jenkins
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...