GHSA-v7g7-cmxx-wxw9
Dashboard / Vulnerabilities / GHSA-v7g7-cmxx-wxw9
Summary: Jenkins GitHub Plugin exposure of sensitive information vulnerability exists
Details: A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-1000183, https://github.com/jenkinsci/github-plugin/commit/775a8be0d4f7238b33cbbda6508170ff34a90736, https://github.com/jenkinsci/github-plugin, https://jenkins.io/security/advisory/2018-06-04/#SECURITY-804
Affected packages
Package
Name: com.coravy.hudson.plugins.github:github
Purl: pkg:maven/com.coravy.hudson.plugins.github/github
Affected ranges
Type: ECOSYSTEM
Events:
