CVE-2018-1999041
Exposure of sensitive information vulnerability
5.5
MEDIUM
CVSS 3.1
EPSS 0.01%
Description
An exposure of sensitive information vulnerability exists in Jenkins Tinfoil Security Plugin 1.6.1 and earlier in TinfoilScanRecorder.java that allows attackers with file system access to the Jenkins master to obtain the API secret key stored in this plugin's configuration.
How to fix CVE-2018-1999041
To remediate CVE-2018-1999041, upgrade the affected package to a fixed version below.
- —upgrade to 2.0 or later
Is CVE-2018-1999041 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |