|
200401
|
5.4 |
MEDIUM
Network
|
jenkins
|
usemango_runner
|
Multiple form validation endpoints in Jenkins useMango Runner Plugin 1.4 and earlier do not escape values received from the useMango service, resulting in a cross-site scripting (XSS) vulnerability e…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2176
|
2024-11-21 14:24 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200402
|
5.4 |
MEDIUM
Network
|
jenkins
|
fitnesse
|
Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2175
|
2024-11-21 14:24 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200403
|
6.1 |
MEDIUM
Network
|
jenkins
|
awseb_deployment
|
Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output, resulting in a reflected cross-site scripting vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2174
|
2024-11-21 14:24 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200404
|
5.4 |
MEDIUM
Network
|
jenkins
|
gatling
|
Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports served by the plugin, resulting in an XSS vulnerability exploitable by users able …
|
CWE-79
Cross-site Scripting
|
CVE-2020-2173
|
2024-11-21 14:24 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200405
|
6.5 |
MEDIUM
Network
|
jenkins
|
code_coverage_api
|
Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
CWE-776
XML Entity Expansion
|
CVE-2020-2172
|
2024-11-21 14:24 |
2020-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200406
|
8.8 |
HIGH
Network
|
jenkins
|
rapiddeploy
|
Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
CWE-611
XXE
|
CVE-2020-2171
|
2024-11-21 14:24 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200407
|
5.4 |
MEDIUM
Network
|
jenkins
|
rapiddeploy
|
Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote server, resulting in a stored XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2170
|
2024-11-21 14:24 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200408
|
6.1 |
MEDIUM
Network
|
jenkins
|
queue_cleanup
|
A form validation endpoint in Jenkins Queue cleanup Plugin 1.3 and earlier does not properly escape a query parameter displayed in an error message, resulting in a reflected XSS vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2169
|
2024-11-21 14:24 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200409
|
8.8 |
HIGH
Network
|
jenkins
|
azure_container_service
|
Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
|
CWE-20
Improper Input Validation
|
CVE-2020-2168
|
2024-11-21 14:24 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200410
|
8.8 |
HIGH
Network
|
jenkins
|
openshift_pipeline
|
Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
|
CWE-20
Improper Input Validation
|
CVE-2020-2167
|
2024-11-21 14:24 |
2020-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|