|
222411
|
8.8 |
HIGH
Network
|
jenkins
|
rapiddeploy
|
A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web server.
|
CWE-352
Origin Validation Error
|
CVE-2019-16570
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222412
|
4.3 |
MEDIUM
Network
|
jenkins
|
mantis
|
A cross-site request forgery vulnerability in Jenkins Mantis Plugin 0.26 and earlier allows attackers to connect to an attacker-specified web server using attacker-specified credentials.
|
CWE-352
Origin Validation Error
|
CVE-2019-16569
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222413
|
5.3 |
MEDIUM
Network
|
jenkins
|
sctmexecutor
|
Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of the global configuration, as well as individual jobs' configurations.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-16568
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222414
|
4.3 |
MEDIUM
Network
|
jenkins
|
team_concert
|
A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
|
CWE-862
Missing Authorization
|
CVE-2019-16567
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222415
|
6.5 |
MEDIUM
Network
|
jenkins
|
team_concert
|
A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials …
|
CWE-862
Missing Authorization
|
CVE-2019-16566
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222416
|
8.8 |
HIGH
Network
|
jenkins
|
team_concert
|
A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained …
|
CWE-352
Origin Validation Error
|
CVE-2019-16565
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222417
|
5.4 |
MEDIUM
Network
|
jenkins
|
pipeline_aggregator_view
|
Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to affects view content su…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16564
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222418
|
5.4 |
MEDIUM
Network
|
jenkins
|
mission_control
|
Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to change …
|
CWE-79
Cross-site Scripting
|
CVE-2019-16563
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222419
|
5.4 |
MEDIUM
Network
|
jenkins
|
buildgraph-view
|
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the description of builds shown in its view, resulting in a stored XSS vulnerability exploitable by users able to change build descripti…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16562
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222420
|
7.1 |
HIGH
Network
|
jenkins
|
websphere_deployer
|
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for the entire Jenkins master JVM.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-16561
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|