|
198761
|
6.5 |
MEDIUM
Network
|
jenkins
|
mercurial
|
Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2020-2305
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198762
|
6.5 |
MEDIUM
Network
|
jenkins
|
subversion
|
Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2020-2304
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198763
|
4.3 |
MEDIUM
Network
|
jenkins
|
active_directory
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously conf…
|
CWE-352
Origin Validation Error
|
CVE-2020-2303
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198764
|
4.3 |
MEDIUM
Network
|
jenkins
|
active_directory
|
A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page.
|
CWE-862
Missing Authorization
|
CVE-2020-2302
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198765
|
9.8 |
CRITICAL
Network
|
jenkins
|
active_directory
|
Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is still in the optional cache when using Wind…
|
-
|
CVE-2020-2301
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198766
|
9.8 |
CRITICAL
Network
|
jenkins
|
active_directory
|
Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configur…
|
-
|
CVE-2020-2300
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198767
|
9.8 |
CRITICAL
Network
|
jenkins
|
active_directory
|
Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.
|
-
|
CVE-2020-2299
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198768
|
6.5 |
MEDIUM
Network
|
jenkins
|
nerrvana
|
Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2020-2298
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198769
|
3.3 |
LOW
Local
|
jenkins
|
sms_notification
|
Jenkins SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkin…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-2297
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198770
|
4.3 |
MEDIUM
Network
|
jenkins
|
shared_objects
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to configure shared objects.
|
CWE-352
Origin Validation Error
|
CVE-2020-2296
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|