6.5
CVSSv3

CVE-2018-1000609

Published: 26/06/2018 Updated: 23/08/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and previous versions in ConfigurationAsCode.java that allows attackers with Overall/Read access to obtain the YAML export of the Jenkins configuration.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins configuration as code 0.2

jenkins configuration as code 0.3

jenkins configuration as code 0.4

jenkins configuration as code 0.5

jenkins configuration as code 0.7

jenkins configuration as code 0.1

jenkins configuration as code 0.6