CVE-2018-1999036

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
01/08/2018
Last modified:
03/10/2019

Description

An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the SSH private key password to users with permission to read the build log.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:ssh_agent:*:*:*:*:*:jenkins:*:* 1.15 (including)


References to Advisories, Solutions, and Tools