CVE-2018-1000603

HIGH

Jenkins Openstack Cloud Plugin <2.35 - Info Disclosure

Title source: llm
STIX 2.1

Description

A exposure of sensitive information vulnerability exists in Jenkins Openstack Cloud Plugin 2.35 and earlier in BootSource.java, InstancesToRun.java, JCloudsCleanupThread.java, JCloudsCloud.java, JCloudsComputer.java, JCloudsPreCreationThread.java, JCloudsRetentionStrategy.java, JCloudsSlave.java, JCloudsSlaveTemplate.java, LauncherFactory.java, OpenstackCredentials.java, OpenStackMachineStep.java, SlaveOptions.java, SlaveOptionsDescriptor.java that allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins, and to cause Jenkins to submit HTTP requests to attacker-specified URLs.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0011
EPSS Percentile 28.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200
Status published
Products (2)
jenkins/openstack_cloud < 2.35
org.jenkins-ci.plugins/openstack-cloud 0 - 2.37Maven
Published Jun 26, 2018
Tracked Since Feb 18, 2026