Sensitive Information Exposure in Jenkins Configuration as Code Plugin
CVE-2018-1000609
6.5MEDIUM
What is CVE-2018-1000609?
A vulnerability in the Jenkins Configuration as Code Plugin allows users with Overall/Read access to exploit the system and retrieve sensitive information in the form of a YAML export of the Jenkins configuration, potentially exposing critical configurations and secrets.