A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file system.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-06-26T17:00:00Z
Updated: 2024-09-16T19:46:57.727Z
Reserved: 2018-06-26T00:00:00Z
Link: CVE-2018-1000601
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-06-26T17:29:00.303
Modified: 2024-11-21T03:40:12.160
Link: CVE-2018-1000601
Redhat