CVE-2018-1000600

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-1000600
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000600.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-1000600
Aliases
Withdrawn
2024-05-15T05:33:06.824395Z
Published
2018-06-26T17:29:00Z
Modified
2023-12-15T15:41:34.358535Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

References

Affected packages

Git / github.com/jenkinsci/github-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/github-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

github-0.*

github-0.3
github-0.4
github-0.5
github-0.6
github-0.7
github-0.8
github-0.9

github-1.*

github-1.0
github-1.1
github-1.10
github-1.11
github-1.11.1
github-1.11.2
github-1.11.3
github-1.12.0
github-1.12.0-alpha-1
github-1.12.1
github-1.13.0
github-1.13.0-alpha-1
github-1.13.0-alpha-2
github-1.14.0
github-1.14.0-alpha-1
github-1.14.0-alpha-2
github-1.14.1
github-1.14.2
github-1.15.0
github-1.16.0
github-1.17.0
github-1.17.1
github-1.18.0
github-1.18.1
github-1.18.2
github-1.19.0
github-1.2
github-1.3
github-1.4
github-1.5
github-1.6
github-1.7
github-1.8
github-1.9
github-1.9.1

v1.*

v1.19.1
v1.19.2
v1.19.3
v1.20.0
v1.21.0
v1.21.1
v1.22.0
v1.22.1
v1.22.2
v1.22.3
v1.22.4
v1.23.0
v1.23.1
v1.24.0
v1.25.1
v1.26.0
v1.26.1
v1.26.2
v1.27.0
v1.28.0
v1.28.1
v1.29.0
v1.29.1