An exposure of sensitive information vulnerability exists in Jenkins Anchore Container Image Scanner Plugin 10.16 and earlier in AnchoreBuilder.java that allows attackers with Item/ExtendedRead permission or file system access to the Jenkins master to obtain the password stored in this plugin's configuration.
Cite this page
CVE-2018-1999033. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2018-1999033
Use CWE-200, Anchore vendor hub and Container Image Scanner product page to widen CVE-2018-1999033 into its surrounding weakness, vendor, and product context.
Additional editorial context is available in Container Security Mastery: A Guide to Scanning Images for Known CVEs.