CVE-2018-1999027: Jenkins SaltStack

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.

Affected products

  • Jenkins SaltStack: up to and including 3.1.6

Published 2018-08-01. Last modified 2026-06-17.