CVE-2018-1000601: Jenkins SSH Credentials

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file system.

Affected products

  • Jenkins SSH Credentials: up to and including 1.13

Published 2018-06-26. Last modified 2026-06-17.