A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to Jenkins log files to obtain the passwords configured using Configuration as Code Plugin.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:21:58

Updated: 2022-10-03T16:21:58

Reserved: 2018-06-25T00:00:00


Link: CVE-2018-1000610

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-06-26T17:29:00.710

Modified: 2019-10-03T00:03:26.223


Link: CVE-2018-1000610

JSON object: View

cve-icon Redhat Information

No data.

CWE