CVE-2018-1000610: High severity jenkins configuration as code vulnerability
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to Jenkins log files to obtain the passwords configured using Configuration as Code Plugin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000610?
CVE-2018-1000610 has been classified as a medium severity vulnerability.
How do I fix CVE-2018-1000610?
To fix CVE-2018-1000610, upgrade the Jenkins Configuration as Code Plugin to version 0.7-alpha or later.
What versions are affected by CVE-2018-1000610?
CVE-2018-1000610 affects Jenkins Configuration as Code Plugin versions 0.1-alpha to 0.7-alpha.
What kind of information can be exposed by CVE-2018-1000610?
CVE-2018-1000610 can expose sensitive information such as passwords found in Jenkins log files.
Who is vulnerable to CVE-2018-1000610?
Attackers with access to Jenkins log files are vulnerable to exploiting CVE-2018-1000610.