MEDIUM
jenkins-plugin-github: CSRF vulnerability and missing permission checks allowed capturing credentials (SECURITY-804)
Published Jun 5, 2018
6.5
MEDIUMCVSS 3.0
EPSS 1.01%
Description
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (2)
References (8)
- https://access.redhat.com/security/cve/CVE-2018-1000183 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1585992 Issue Tracking
- https://github.com/advisories/GHSA-v7g7-cmxx-wxw9 Advisory
- https://github.com/jenkinsci/github-plugin/commit/775a8be0d4f7238b33cbbda6508170ff34a90736
- https://jenkins.io/security/advisory/2018-06-04/
- https://jenkins.io/security/advisory/2018-06-04/#SECURITY-804 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000183
- https://www.cve.org/CVERecord?id=CVE-2018-1000183
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 5, 2018
Updated Sep 17, 2024
Reserved Jun 5, 2018
Link CVE-2018-1000183
CISA Vulnrichment
GHSA-V7G7-CMXX-WXW9 Updated n/a