|
200471
|
5.4 |
MEDIUM
Network
|
jenkins
|
code_coverage_api
|
Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view, resulting in a stored XSS vulnerability exploitable by users able to change jo…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2106
|
2024-11-21 14:24 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200472
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-2105
|
2024-11-21 14:24 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200473
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.
|
CWE-863
Incorrect Authorization
|
CVE-2020-2104
|
2024-11-21 14:24 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200474
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
|
CWE-200
Information Exposure
|
CVE-2020-2103
|
2024-11-21 14:24 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200475
|
5.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-2102
|
2024-11-21 14:24 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200476
|
5.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-2101
|
2024-11-21 14:24 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200477
|
5.8 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848.
|
NVD-CWE-Other
|
CVE-2020-2100
|
2024-11-21 14:24 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200478
|
8.6 |
HIGH
Network
|
jenkins
|
jenkins
|
Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to ob…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-2099
|
2024-11-21 14:24 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200479
|
8.8 |
HIGH
Network
|
jenkins
|
sounds
|
A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user account running Jenkins.
|
CWE-352
Origin Validation Error
|
CVE-2020-2098
|
2024-11-21 14:24 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200480
|
8.8 |
HIGH
Network
|
jenkins
|
sounds
|
Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read access to execute arbitrary OS commands as the OS use…
|
CWE-863
Incorrect Authorization
|
CVE-2020-2097
|
2024-11-21 14:24 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|