CVE-2018-1000187: Infoleak
Published Jun 5, 2018
·Updated
A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive variables such as passwords being written to logs.
Affected Software
1 affected component
Jenkins Kubernetes Jenkins<=1.7.0
Event History
Jun 5, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-1000187?
CVE-2018-1000187 is categorized as a medium severity vulnerability due to the risk of exposing sensitive information.
2
How do I fix CVE-2018-1000187?
To fix CVE-2018-1000187, update the Jenkins Kubernetes Plugin to version 1.7.1 or later.
3
What types of sensitive information are exposed in CVE-2018-1000187?
CVE-2018-1000187 can expose sensitive variables such as passwords in the Jenkins logs.
4
Which versions of Jenkins Kubernetes Plugin are affected by CVE-2018-1000187?
Jenkins Kubernetes Plugin versions 1.7.0 and older are affected by CVE-2018-1000187.
5
Is my Jenkins installation vulnerable to CVE-2018-1000187?
If your Jenkins installation is using the Kubernetes Plugin version 1.7.0 or older, it is vulnerable to CVE-2018-1000187.