CVE-2018-1999036

MEDIUM

Jenkins SSH Agent Plugin <1.15 - Info Disclosure

Title source: llm
STIX 2.1

Description

An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the SSH private key password to users with permission to read the build log.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (2)
jenkins/ssh_agent < 1.15
org.jenkins-ci.plugins/ssh-agent 0 - 1.16Maven
Published Aug 01, 2018
Tracked Since Feb 18, 2026