Description
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6cvm-v6qj-hjq9 | CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T23:01:52.921Z
Reserved: 2018-06-26T00:00:00.000Z
Link: CVE-2018-1000600
No data.
Status : Modified
Published: 2018-06-26T17:29:00.257
Modified: 2024-11-21T03:40:12.003
Link: CVE-2018-1000600
OpenCVE Enrichment
No data.
Github GHSA