|
198781
|
4.3 |
MEDIUM
Network
|
jenkins
|
liquibase_runner
|
A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
|
CWE-862
Missing Authorization
|
CVE-2020-2285
|
2024-11-21 14:25 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198782
|
7.1 |
HIGH
Network
|
jenkins
|
liquibase_runner
|
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
CWE-611
XXE
|
CVE-2020-2284
|
2024-11-21 14:25 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198783
|
5.4 |
MEDIUM
Network
|
jenkins
|
liquibase_runner
|
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control changeset fil…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2283
|
2024-11-21 14:25 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198784
|
4.3 |
MEDIUM
Network
|
jenkins
|
implied_labels
|
Jenkins Implied Labels Plugin 0.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to configure the plugin.
|
CWE-862
Missing Authorization
|
CVE-2020-2282
|
2024-11-21 14:25 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198785
|
5.4 |
MEDIUM
Network
|
jenkins
|
lockable_resources
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers to reserve, unreserve, unlock, and reset resources.
|
CWE-352
Origin Validation Error
|
CVE-2020-2281
|
2024-11-21 14:25 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198786
|
8.8 |
HIGH
Network
|
jenkins
|
warnings
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Warnings Plugin 5.0.1 and earlier allows attackers to execute arbitrary code.
|
CWE-352
Origin Validation Error
|
CVE-2020-2280
|
2024-11-21 14:25 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198787
|
9.9 |
CRITICAL
Network
|
jenkins
|
script_security
|
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to define sandboxed scripts to provide crafted return values or script binding conte…
|
NVD-CWE-noinfo
|
CVE-2020-2279
|
2024-11-21 14:25 |
2020-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198788
|
6.5 |
MEDIUM
Network
|
jenkins
|
storable_configs
|
Jenkins Storable Configs Plugin 1.0 and earlier does not restrict the user-specified file name, allowing attackers with Job/Configure permission to replace any other '.xml' file on the Jenkins contro…
|
CWE-22
Path Traversal
|
CVE-2020-2278
|
2024-11-21 14:25 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198789
|
6.5 |
MEDIUM
Network
|
jenkins
|
storable_configs
|
Jenkins Storable Configs Plugin 1.0 and earlier allows users with Job/Read permission to read arbitrary files on the Jenkins controller.
|
CWE-22
Path Traversal
|
CVE-2020-2277
|
2024-11-21 14:25 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198790
|
8.8 |
HIGH
Network
|
jenkins
|
selection_tasks
|
Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing attackers with Job/Configure permission to execute an arbitrary system command on …
|
CWE-78
OS Command
|
CVE-2020-2276
|
2024-11-21 14:25 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|