4
CVSSv2

CVE-2018-1000601

Published: 26/06/2018 Updated: 17/08/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and previous versions in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins ssh credentials

Vendor Advisories

A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 113 and earlier in BasicSSHUserPrivateKeyjava that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file system ...