HIGH
jenkins-plugin-github: CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials (SECURITY-915)
Published Jun 26, 2018
8.8
HIGHCVSS 3.0
EPSS 90.89%
Description
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (2)
References (8)
- https://access.redhat.com/security/cve/CVE-2018-1000600 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1596120 Issue Tracking
- https://github.com/advisories/GHSA-6cvm-v6qj-hjq9 Advisory
- https://github.com/jenkinsci/github-plugin/commit/ce7f5f2cb523757f2bf9ec362e1c8de1de447ec7
- https://jenkins.io/security/advisory/2018-06-25/
- https://jenkins.io/security/advisory/2018-06-25/#SECURITY-915 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000600
- https://www.cve.org/CVERecord?id=CVE-2018-1000600
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 26, 2018
Updated Sep 16, 2024
Reserved Jun 26, 2018
Link CVE-2018-1000600
CISA Vulnrichment
GHSA-6CVM-V6QJ-HJQ9 Updated n/a