GHSA-92rv-mvmj-47qh
Dashboard / Vulnerabilities / GHSA-92rv-mvmj-47qh
Summary: Jenkins GitHub Pull Request Builder Plugin credential capture vulnerability
Details: A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. Additionally, these form validation methods did not require POST requests, resulting in a CSRF vulnerability. As of version 1.42.0, these form validation methods require POST requests and Overall/Administer permissions.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-1000186, https://github.com/jenkinsci/ghprb-plugin/commit/e78ee24f7056b8507992ef17a9bb74a1a31d8c11, https://github.com/jenkinsci/ghprb-plugin, https://jenkins.io/security/advisory/2018-06-04/#SECURITY-805, https://mvnrepository.com/artifact/org.jenkins-ci.plugins/ghprb
Affected packages
Package
Name: org.jenkins-ci.plugins:ghprb
Purl: pkg:maven/org.jenkins-ci.plugins/ghprb
Affected ranges
Type: ECOSYSTEM
Events:
