Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Configuration As Code
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1000610 1 Jenkins 1 Configuration As Code 2019-10-03 4.0 MEDIUM 8.8 HIGH
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to Jenkins log files to obtain the passwords configured using Configuration as Code Plugin.