CVE-2018-1999040: Infoleak
Published Aug 1, 2018
·Updated
An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
Affected Software
2 affected componentsFixes available
maven/org.csanchez.jenkins.plugins:kubernetes<=1.10.1
1.10.2
Jenkins Kubernetes Jenkins<=1.10.1
Event History
Aug 1, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
May 13, 2022
Advisory Published
01:50 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-1999040?
CVE-2018-1999040 is rated as medium severity due to its potential exposure of sensitive information.
2
How do I fix CVE-2018-1999040?
To fix CVE-2018-1999040, upgrade the Jenkins Kubernetes Plugin to version 1.10.2 or later.
3
What versions are affected by CVE-2018-1999040?
CVE-2018-1999040 affects Jenkins Kubernetes Plugin versions 1.10.1 and earlier.
4
What kind of data can be exposed by CVE-2018-1999040?
CVE-2018-1999040 can expose credentials associated with known credentials IDs stored in Jenkins.
5
What is the impact of CVE-2018-1999040?
The impact of CVE-2018-1999040 is that it allows attackers to capture sensitive credentials from Jenkins.