Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1999040

Опубликовано: 30 июл. 2018
Источник: redhat
CVSS3: 4.8

Описание

An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.10jenkins-plugin-kubernetesWill not fix
Red Hat OpenShift Container Platform 3.11jenkins-plugin-kubernetesNot affected
Red Hat OpenShift Container Platform 3.2jenkins-plugin-kubernetesWill not fix
Red Hat OpenShift Container Platform 3.3jenkins-plugin-kubernetesWill not fix
Red Hat OpenShift Container Platform 3.4jenkins-plugin-kubernetesWill not fix
Red Hat OpenShift Container Platform 3.5jenkins-plugin-kubernetesWill not fix
Red Hat OpenShift Container Platform 3.6jenkins-plugin-kubernetesWill not fix
Red Hat OpenShift Container Platform 3.7jenkins-plugin-kubernetesWill not fix
Red Hat OpenShift Container Platform 3.9jenkins-plugin-kubernetesWill not fix
Red Hat OpenShift Enterprise 3.1jenkins-plugin-kubernetesWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1611846jenkins-plugin-kubernetes: credentials Information Exposure

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
почти 7 лет назад

An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.

CVSS3: 8.8
github
около 3 лет назад

Exposure of Sensitive Information in Jenkins Kubernetes Plugin

4.8 Medium

CVSS3