CVE-2018-1000600
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
- Affected products
- Jenkins, Jenkins Git Plugin
- Jenkins Github
- ≤ 1.29.1
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 90.9% (100th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2018-06-26
CVE-2018-1000600 at NVD
No indexed exploits for CVE-2018-1000600 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-1000600 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.