{"id":"GHSA-92rv-mvmj-47qh","summary":"Jenkins GitHub Pull Request Builder Plugin credential capture vulnerability","details":"A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. Additionally, these form validation methods did not require POST requests, resulting in a CSRF vulnerability. As of version 1.42.0, these form validation methods require POST requests and Overall/Administer permissions.","aliases":["CVE-2018-1000186"],"modified":"2024-12-05T16:29:45.406936Z","published":"2022-05-14T03:13:13Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-12-12T16:47:40Z","nvd_published_at":"2018-06-05T20:29:00Z","cwe_ids":["CWE-200"],"severity":"LOW"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1000186"},{"type":"WEB","url":"https://github.com/jenkinsci/ghprb-plugin/commit/e78ee24f7056b8507992ef17a9bb74a1a31d8c11"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/ghprb-plugin"},{"type":"WEB","url":"https://jenkins.io/security/advisory/2018-06-04/#SECURITY-805"},{"type":"WEB","url":"https://mvnrepository.com/artifact/org.jenkins-ci.plugins/ghprb"}],"affected":[{"package":{"name":"org.jenkins-ci.plugins:ghprb","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/ghprb"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.42.0"}]}],"versions":["1.0","1.1","1.1.1","1.11.2","1.12","1.13","1.13-1","1.14","1.14-1","1.14-2","1.14-3","1.14-4","1.14-5","1.14-6","1.14-7","1.15-0","1.15-1","1.16-0","1.16-1","1.16-2","1.16-3","1.16-4","1.16-5","1.16-6","1.16-7","1.16-8","1.17","1.18","1.19","1.2","1.20","1.20.1","1.21","1.21.1","1.22","1.22.1","1.22.2","1.22.3","1.22.4","1.23","1.23.1","1.23.2","1.23.3","1.24","1.24.1","1.24.2","1.24.3","1.24.4","1.24.5","1.24.6","1.24.7","1.24.8","1.25","1.26","1.26.1","1.26.2","1.27","1.28","1.28.1","1.28.2","1.28.3","1.28.4","1.28.6","1.29","1.29.1","1.29.2","1.29.3","1.29.4","1.29.5","1.29.6","1.29.7","1.29.8","1.3","1.3.1","1.3.2","1.30","1.30.1","1.30.2","1.30.3","1.30.4","1.30.5","1.30.6","1.31.1","1.31.2","1.31.3","1.31.4","1.32.1","1.32.2","1.32.3","1.32.4","1.32.5","1.32.6","1.32.7","1.32.8","1.33.0","1.33.1","1.33.2","1.33.3","1.33.4","1.34.0","1.35.0","1.36.0","1.36.1","1.36.2","1.37.0","1.38.0","1.39.0","1.4","1.40.0","1.41.0","1.5","1.5.1","1.7","1.8","1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-92rv-mvmj-47qh/GHSA-92rv-mvmj-47qh.json","last_known_affected_version_range":"\u003c= 1.41.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}