CVE-2018-1000600 is a sensitive information exposure vulnerability in Jenkins GitHub Plugin versions 1.29.1 and earlier. It allows attackers to craft a malicious request that forces Jenkins to connect to an attacker-controlled URL using credentials stored within Jenkins, thereby exfiltrating those credentials. This vulnerability has a high CVSS score of 8.8, indicating a critical risk due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or Metasploit modules, a Nuclei template exists for Server-Side Request Forgery, and the vulnerability has a very high EPSS score, suggesting a significant likelihood of future exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.29.1CPE matchmatch criteria | cpe:2.3:a:jenkins:github:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials
May 13, 2022jenkins-plugin-github: CSRF vulnerability and missing permission checks in GitHub Plugin allowed capturing credentials (SECURITY-915)
Jun 25, 2018