First published: Wed Aug 01 2018(Updated: )
An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.csanchez.jenkins.plugins:kubernetes | <=1.10.1 | 1.10.2 |
Jenkins Kubernetes | <=1.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1999040 is rated as medium severity due to its potential exposure of sensitive information.
To fix CVE-2018-1999040, upgrade the Jenkins Kubernetes Plugin to version 1.10.2 or later.
CVE-2018-1999040 affects Jenkins Kubernetes Plugin versions 1.10.1 and earlier.
CVE-2018-1999040 can expose credentials associated with known credentials IDs stored in Jenkins.
The impact of CVE-2018-1999040 is that it allows attackers to capture sensitive credentials from Jenkins.