|
199551
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2221
|
2024-11-21 14:24 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199552
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2220
|
2024-11-21 14:24 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199553
|
8.1 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with root privileges. An attacker requires s…
|
CWE-78
OS Command
|
CVE-2020-2034
|
2024-11-21 14:24 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199554
|
4.9 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
An integer underflow vulnerability in the dnsproxyd component of the PAN-OS management interface allows authenticated administrators to issue a command from the command line interface that causes the…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2020-2031
|
2024-11-21 14:24 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199555
|
7.2 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts PAN-OS 8.1 …
|
CWE-78
OS Command
|
CVE-2020-2030
|
2024-11-21 14:24 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199556
|
5.4 |
MEDIUM
Network
|
jenkins
|
link_column
|
Jenkins Link Column Plugin 1.0 and earlier does not filter URLs of links created by users with View/Configure permission, resulting in a stored cross-site scripting vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2219
|
2024-11-21 14:24 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199557
|
3.3 |
LOW
Local
|
hp_application_lifecycle_management_quality_center_project
|
hp_application_lifecycle_management_quality_center
|
Jenkins HP ALM Quality Center Plugin 1.6 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master fil…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-2218
|
2024-11-21 14:24 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199558
|
6.1 |
MEDIUM
Network
|
praqma
|
compatibility_action_storage
|
Jenkins Compatibility Action Storage Plugin 1.0 and earlier does not escape the content coming from the MongoDB in the testConnection form validation endpoint, resulting in a reflected cross-site scr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2217
|
2024-11-21 14:24 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199559
|
4.3 |
MEDIUM
Network
|
jenkins
|
zephyr_for_jira_test_management
|
A missing permission check in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attack…
|
CWE-862
Missing Authorization
|
CVE-2020-2216
|
2024-11-21 14:24 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199560
|
4.3 |
MEDIUM
Network
|
jenkins
|
zephyr_for_jira_test_management
|
A cross-site request forgery vulnerability in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified …
|
CWE-352
Origin Validation Error
|
CVE-2020-2215
|
2024-11-21 14:24 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|