|
199381
|
8.8 |
HIGH
Network
|
jenkins
|
speaks\!
|
Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effectively elevating privileges to Overall/Run Scripts.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-1000403
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199382
|
5.9 |
MEDIUM
Network
|
jenkins
|
swarm
|
Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible …
|
CWE-20
Improper Input Validation
|
CVE-2017-1000402
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199383
|
2.2 |
LOW
Local
|
jenkins
|
jenkins
|
The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, <f:password/>, supports form validation (e.g. for API keys). The form validation AJAX requests w…
|
CWE-20
Improper Input Validation
|
CVE-2017-1000401
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199384
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current…
|
CWE-862
Missing Authorization
|
CVE-2017-1000400
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199385
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in the queue (typically builds waiting to start). This included information about ta…
|
CWE-200
Information Exposure
|
CVE-2017-1000399
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199386
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
The remote API in Jenkins 2.73.1 and earlier, 2.83 and earlier at /computer/(agent-name)/api showed information about tasks (typically builds) currently running on that agent. This included informati…
|
CWE-200
Information Exposure
|
CVE-2017-1000398
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199387
|
5.9 |
MEDIUM
Network
|
jenkins
|
maven
|
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man…
|
CWE-20
Improper Input Validation
|
CVE-2017-1000397
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199388
|
5.9 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-1000396
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199389
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.73.1 and earlier, 2.83 and earlier provides information about Jenkins user accounts which is generally available to anyone with Overall/Read permissions via the /user/(username)/api remote …
|
CWE-200
Information Exposure
|
CVE-2017-1000395
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199390
|
7.5 |
HIGH
Network
|
jenkins
|
jenkins
|
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has be…
|
CWE-20
Improper Input Validation
|
CVE-2017-1000394
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|