CVE Vulnerabilities

CVE-2018-1999036

Insertion of Sensitive Information into Log File

Published: Aug 01, 2018 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the SSH private key password to users with permission to read the build log.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Ssh_agent Jenkins * 1.15 (including)

Potential Mitigations

References