CVE-2018-1999028: Infoleak
Published Aug 1, 2018
·Updated
An exposure of sensitive information vulnerability exists in Jenkins Accurev Plugin 0.7.16 and earlier in AccurevSCM.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Affected Software
1 affected component
Jenkins Accurev Jenkins<=0.7.16
Event History
Aug 1, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-1999028?
CVE-2018-1999028 is rated as a medium severity vulnerability.
2
How do I fix CVE-2018-1999028?
To fix CVE-2018-1999028, update the Jenkins Accurev Plugin to version 0.7.17 or later.
3
What types of credentials are affected by CVE-2018-1999028?
CVE-2018-1999028 affects credentials with a known credentials ID stored in Jenkins.
4
Which versions of the Jenkins Accurev Plugin are vulnerable in CVE-2018-1999028?
Versions 0.7.16 and earlier of the Jenkins Accurev Plugin are vulnerable to CVE-2018-1999028.
5
What can attackers do with CVE-2018-1999028?
Attackers can capture sensitive credentials stored in Jenkins due to CVE-2018-1999028.