CVE-2018-1000610

EUVD-2022-3100
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to Jenkins log files to obtain the passwords configured using Configuration as Code Plugin.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Affected Products (NVD)
VendorProductVersion
jenkinsconfiguration_as_code
0.1:alpha
jenkinsconfiguration_as_code
0.2:alpha
jenkinsconfiguration_as_code
0.3:alpha
jenkinsconfiguration_as_code
0.4:alpha
jenkinsconfiguration_as_code
0.5:alpha
jenkinsconfiguration_as_code
0.6:alpha
jenkinsconfiguration_as_code
0.7:alpha
𝑥
= Vulnerable software versions