First published: Thu Apr 05 2018(Updated: )
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Github Pull Request Builder | <=1.39.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000143 has a high severity rating due to the potential exposure of sensitive GitHub credentials.
To fix CVE-2018-1000143, upgrade the Jenkins GitHub Pull Request Builder Plugin to version 1.40.0 or later.
CVE-2018-1000143 affects Jenkins GitHub Pull Request Builder Plugin versions up to and including 1.39.0.
The risks include unauthorized access to GitHub credentials by an attacker with local file system access.
More detailed information about CVE-2018-1000143 can typically be found in security advisories from Jenkins.