Vulnerability record · CVE-2018-1000600 · published 26 June 2018
CVE-2018-1000600: Jenkins GitHub Plugin credential exposure via attacker-specified URL
Jenkins · Github
The Jenkins GitHub Plugin 1.29.1 and earlier contains an information exposure flaw in GitHubTokenCredentialsCreator.java. An attacker can direct the plugin to an attacker-controlled URL using credential IDs obtained through another method, causing Jenkins to send stored credentials to that URL. This exposes credentials held by Jenkins to an external party.
Description
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 and an EPSS probability above 0.90 indicate a serious, likely-exploited credential exposure, though it is not in KEV and requires user interaction.
What it is
The Jenkins GitHub Plugin 1.29.1 and earlier contains an information exposure flaw in GitHubTokenCredentialsCreator.java. An attacker can direct the plugin to an attacker-controlled URL using credential IDs obtained through another method, causing Jenkins to send stored credentials to that URL. This exposes credentials held by Jenkins to an external party.
Impact
An attacker gains access to credentials stored in Jenkins, which can then be used to reach downstream systems and repositories those credentials protect. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The vulnerability is network-reachable (AV:N) with low attack complexity and no privileges required, but it does require user interaction (UI:R), meaning a victim must trigger the crafted request. No authentication is needed to reach the vulnerable code path per the vector.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.90894 (99.8th percentile), indicating strong likelihood of exploitation activity. The only references are the vendor advisory, so no public exploit details are confirmed in this record.
What to do
- Upgrade the Jenkins GitHub Plugin to a version later than 1.29.1 as directed by the Jenkins security advisory SECURITY-915.
- Rotate any credentials stored in Jenkins that may have been exposed, especially GitHub tokens and related secrets.
- Restrict outbound network access from the Jenkins controller so it cannot reach arbitrary attacker-controlled URLs.
- Limit who can configure or trigger jobs that use the GitHub Plugin, since user interaction is part of the attack path.
Detection
- Monitor Jenkins controller outbound HTTP requests for connections to unexpected or external URLs.
- Audit Jenkins logs for GitHub Plugin credential creation or usage events tied to unusual credential IDs or destinations.
- Review Jenkins credential usage for tokens being sent to hosts outside the expected GitHub domains.
- Alert on changes to GitHub Plugin configuration or jobs that introduce attacker-controlled URLs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jenkins.io/security/advisory/2018-06-25/#SECURITY-915 | Vendor Advisory |
| https://jenkins.io/security/advisory/2018-06-25/#SECURITY-915 | Vendor Advisory |
Track CVE-2018-1000600 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1000600), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.