Vulnerability Details CVE-2018-1000601
A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 58.6%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2018-1000601
-
cpe:2.3:a:jenkins:ssh_credentials:0.1
-
cpe:2.3:a:jenkins:ssh_credentials:0.2
-
cpe:2.3:a:jenkins:ssh_credentials:0.3
-
cpe:2.3:a:jenkins:ssh_credentials:0.4
-
cpe:2.3:a:jenkins:ssh_credentials:1.0
-
cpe:2.3:a:jenkins:ssh_credentials:1.1
-
cpe:2.3:a:jenkins:ssh_credentials:1.10
-
cpe:2.3:a:jenkins:ssh_credentials:1.11
-
cpe:2.3:a:jenkins:ssh_credentials:1.12
-
cpe:2.3:a:jenkins:ssh_credentials:1.13
-
cpe:2.3:a:jenkins:ssh_credentials:1.2
-
cpe:2.3:a:jenkins:ssh_credentials:1.3
-
cpe:2.3:a:jenkins:ssh_credentials:1.4
-
cpe:2.3:a:jenkins:ssh_credentials:1.5
-
cpe:2.3:a:jenkins:ssh_credentials:1.5.1
-
cpe:2.3:a:jenkins:ssh_credentials:1.6
-
cpe:2.3:a:jenkins:ssh_credentials:1.6.1
-
cpe:2.3:a:jenkins:ssh_credentials:1.7
-
cpe:2.3:a:jenkins:ssh_credentials:1.7.1
-
cpe:2.3:a:jenkins:ssh_credentials:1.8
-
cpe:2.3:a:jenkins:ssh_credentials:1.9