VYPR

SSH Credentials

by Jenkins Project

CVEs (1)

  • CVE-2018-1000601MedJun 26, 2018
    risk 0.35cvss 6.5epss 0.01

    A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file…