Filtered by vendor Jenkins
Subscribe
Total
1395 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-10433 | 1 Jenkins | 1 Dingding | 2023-03-01 | 2.1 LOW | 3.3 LOW |
Jenkins Dingding[??] Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |||||
CVE-2022-43403 | 1 Jenkins | 1 Script Security | 2023-02-28 | N/A | 9.9 CRITICAL |
A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. | |||||
CVE-2019-10429 | 1 Jenkins | 1 Gitlab Logo | 2023-02-28 | 2.1 LOW | 5.5 MEDIUM |
Jenkins GitLab Logo Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |||||
CVE-2019-10427 | 1 Jenkins | 1 Aqua Microscanner | 2023-02-28 | 5.0 MEDIUM | 5.3 MEDIUM |
Jenkins Aqua MicroScanner Plugin 1.0.7 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. | |||||
CVE-2019-10426 | 1 Jenkins | 1 Gem Publisher | 2023-02-28 | 2.1 LOW | 5.5 MEDIUM |
Jenkins Gem Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |||||
CVE-2019-10425 | 1 Jenkins | 1 Google Calendar | 2023-02-28 | 4.0 MEDIUM | 6.5 MEDIUM |
Jenkins Google Calendar Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |||||
CVE-2019-10428 | 1 Jenkins | 1 Aqua Security Scanner | 2023-02-28 | 5.0 MEDIUM | 7.5 HIGH |
Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. | |||||
CVE-2019-10398 | 1 Jenkins | 1 Beaker Builder | 2023-02-28 | 2.1 LOW | 5.5 MEDIUM |
Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system. | |||||
CVE-2019-10396 | 1 Jenkins | 1 Dashboard View | 2023-02-28 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vulnerability exploitable by users able to change build descriptions. | |||||
CVE-2019-10395 | 1 Jenkins | 1 Build Environment | 2023-02-28 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Jenkins 2.145, 2.138.1, or older, exploitable by users able to change various job/build properties. | |||||
CVE-2019-10392 | 1 Jenkins | 1 Git Client | 2023-02-28 | 6.5 MEDIUM | 8.8 HIGH |
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection. | |||||
CVE-2023-25767 | 1 Jenkins | 1 Azure Credentials | 2023-02-24 | N/A | 8.8 HIGH |
A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers to connect to an attacker-specified web server. | |||||
CVE-2023-23850 | 1 Jenkins | 1 Synopsys Coverity | 2023-02-22 | N/A | 4.3 MEDIUM |
A missing permission check in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |||||
CVE-2023-25763 | 1 Jenkins | 1 Email Extension | 2023-02-22 | N/A | 5.4 MEDIUM |
Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control affected fields. | |||||
CVE-2023-25764 | 1 Jenkins | 1 Email Extension | 2023-02-22 | N/A | 5.4 MEDIUM |
Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or change custom email templates. | |||||
CVE-2023-25762 | 1 Jenkins | 1 Pipeline\ | 2023-02-22 | N/A | 5.4 MEDIUM |
Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pipeline Snippet Generator, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control job names. | |||||
CVE-2023-25761 | 1 Jenkins | 1 Junit | 2023-02-22 | N/A | 5.4 MEDIUM |
Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin. | |||||
CVE-2023-23847 | 1 Jenkins | 1 Synopsys Coverity | 2023-02-22 | N/A | 3.5 LOW |
A cross-site request forgery (CSRF) vulnerability in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |||||
CVE-2023-25765 | 1 Jenkins | 1 Email Extension | 2023-02-22 | N/A | 9.9 CRITICAL |
In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. | |||||
CVE-2023-23848 | 1 Jenkins | 1 Synopsys Coverity | 2023-02-22 | N/A | 4.3 MEDIUM |
Missing permission checks in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. |