|
198741
|
5.3 |
MEDIUM
Network
|
netflix
|
chaos_monkey
|
Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission to access the Chaos Monkey page and to see the hist…
|
CWE-862
Missing Authorization
|
CVE-2020-2323
|
2024-11-21 14:25 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198742
|
7.5 |
HIGH
Network
|
netflix
|
chaos_monkey
|
Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks.
|
CWE-862
Missing Authorization
|
CVE-2020-2322
|
2024-11-21 14:25 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198743
|
8.1 |
HIGH
Network
|
jenkins
|
shelve_project
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to shelve, unshelve, or delete a project.
|
CWE-352
Origin Validation Error
|
CVE-2020-2321
|
2024-11-21 14:25 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198744
|
9.8 |
CRITICAL
Network
|
jenkins
|
installation_manager_tool
|
Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-2320
|
2024-11-21 14:25 |
2020-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198745
|
7.2 |
HIGH
Network
|
qnap
|
qts
|
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
|
CWE-77
Command Injection
|
CVE-2020-2492
|
2024-11-21 14:25 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198746
|
7.2 |
HIGH
Network
|
qnap
|
qts
|
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
|
CWE-77
Command Injection
|
CVE-2020-2490
|
2024-11-21 14:25 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198747
|
6.5 |
MEDIUM
Network
|
jenkins
|
vmware_lab_manager_slaves
|
Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jen…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-2319
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198748
|
6.5 |
MEDIUM
Network
|
jenkins
|
mail_commander
|
Jenkins Mail Commander Plugin for Jenkins-ci Plugin 1.0.0 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Re…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-2318
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198749
|
5.4 |
MEDIUM
Network
|
jenkins
|
findbugs
|
Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide r…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2317
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198750
|
5.4 |
MEDIUM
Network
|
jenkins
|
static_analysis_utilities
|
Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2316
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|