CVE-2018-1999036: Inclusion of Sensitive Information in Log Files
(updated )
An exposure of sensitive information vulnerability exists in the Jenkins SSH Agent Plugin in SSHAgentStepExecution.java
that exposes the SSH private key password to users with permission to read the build log.
References
Detect and mitigate CVE-2018-1999036 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →