CVE-2018-1000610

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to Jenkins log files to obtain the passwords configured using Configuration as Code Plugin.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
jenkinsconfiguration_as_code
0.1:alpha
jenkinsconfiguration_as_code
0.2:alpha
jenkinsconfiguration_as_code
0.3:alpha
jenkinsconfiguration_as_code
0.4:alpha
jenkinsconfiguration_as_code
0.5:alpha
jenkinsconfiguration_as_code
0.6:alpha
jenkinsconfiguration_as_code
0.7:alpha
𝑥
= Vulnerable software versions