Credential Exposure in GitHub Branch Source by CloudBees
CVE-2017-1000087
4.3MEDIUM
Key Information:
- Vendor
Jenkins
- Status
- Vendor
- CVE Published:
- 5 October 2017
What is CVE-2017-1000087?
The GitHub Branch Source Plugin by CloudBees exposes a list of valid credential IDs without proper permission checks. Users with Overall/Read permissions can access these IDs, posing a security risk as unauthorized users may exploit this information to retrieve sensitive credentials and gain unauthorized access through related vulnerabilities.