|
198771
|
6.5 |
MEDIUM
Network
|
barchart
|
maven_cascade_release
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attackers to start cascade builds and layout builds, and reconfigure the plugin.
|
CWE-352
Origin Validation Error
|
CVE-2020-2295
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198772
|
6.5 |
MEDIUM
Network
|
barchart
|
maven_cascade_release
|
Jenkins Maven Cascade Release Plugin 1.3.2 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to start cascade builds and layout…
|
-
|
CVE-2020-2294
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198773
|
6.5 |
MEDIUM
Network
|
jenkins
|
persona
|
Jenkins Persona Plugin 2.4 and earlier allows users with Overall/Read permission to read arbitrary files on the Jenkins controller.
|
-
|
CVE-2020-2293
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198774
|
5.4 |
MEDIUM
Network
|
jenkins
|
release
|
Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Release/Re…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2292
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198775
|
3.3 |
LOW
Local
|
jenkins
|
couchdb-statistics
|
Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-2291
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198776
|
5.4 |
MEDIUM
Network
|
jenkins
|
active_choices
|
Jenkins Active Choices Plugin 2.4 and earlier does not escape some return values of sandboxed scripts for Reactive Reference Parameters, resulting in a stored cross-site scripting (XSS) vulnerability…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2290
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198777
|
5.4 |
MEDIUM
Network
|
jenkins
|
active_choices
|
Jenkins Active Choices Plugin 2.4 and earlier does not escape the name and description of build parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers wit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2289
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198778
|
5.3 |
MEDIUM
Network
|
jenkins
|
audit_trail
|
In Jenkins Audit Trail Plugin 3.6 and earlier, the default regular expression pattern could be bypassed in many cases by adding a suffix to the URL that would be ignored during request handling.
|
-
|
CVE-2020-2288
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198779
|
5.3 |
MEDIUM
Network
|
jenkins
|
audit_trail
|
Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework uses for dispatching requests, which allows attac…
|
-
|
CVE-2020-2287
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198780
|
8.8 |
HIGH
Network
|
jenkins
|
role-based_authorization_strategy
|
Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when the configuration is changed, resulting in permissions being granted based on an …
|
-
|
CVE-2020-2286
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|