Description
A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3646 | A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file system. |
Github GHSA |
GHSA-cwcf-5m5w-mq2w | Exposure of Sensitive Information to an Unauthorized Actor in Jenkins SSH Credentials Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T19:46:57.727Z
Reserved: 2018-06-26T00:00:00.000Z
Link: CVE-2018-1000601
No data.
Status : Modified
Published: 2018-06-26T17:29:00.303
Modified: 2024-11-21T03:40:12.160
Link: CVE-2018-1000601
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA