CVE-2018-1000186: Infoleak
A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000186?
The severity of CVE-2018-1000186 is classified as high due to the potential exposure of sensitive information.
How do I fix CVE-2018-1000186?
To fix CVE-2018-1000186, update the Jenkins GitHub Pull Request Builder Plugin to version 1.42.0 or later.
What versions of Jenkins are affected by CVE-2018-1000186?
CVE-2018-1000186 affects Jenkins GitHub Pull Request Builder Plugin versions 1.41.0 and older.
What kind of information is exposed in CVE-2018-1000186?
CVE-2018-1000186 can expose sensitive information by allowing attackers to connect to specified URLs using attacker-controlled credentials.
Who is at risk from CVE-2018-1000186?
Users with Overall/Read access to the Jenkins GitHub Pull Request Builder Plugin are at risk from CVE-2018-1000186.