Vulnerability Description
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to Jenkins log files to obtain the passwords configured using Configuration as Code Plugin.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Configuration As Code | 0.1 |
Related Weaknesses (CWE)
References
- https://jenkins.io/security/advisory/2018-06-25/#SECURITY-929Vendor Advisory
- https://jenkins.io/security/advisory/2018-06-25/#SECURITY-929Vendor Advisory
FAQ
What is CVE-2018-1000610?
CVE-2018-1000610 is a vulnerability with a CVSS score of 8.8 (HIGH). A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionCo...
How severe is CVE-2018-1000610?
CVE-2018-1000610 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1000610?
Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Configuration As Code.