|
198831
|
6.5 |
MEDIUM
Network
|
jenkins
|
pipeline_maven_integration
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows attackers to connect to an attacker-specified JDBC URL using attacker-specified…
|
CWE-352
Origin Validation Error
|
CVE-2020-2235
|
2024-11-21 14:25 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198832
|
6.5 |
MEDIUM
Network
|
jenkins
|
pipeline_maven_integration
|
A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to connect to an attacker-specified JDBC URL using attacker-specified c…
|
CWE-862
Missing Authorization
|
CVE-2020-2234
|
2024-11-21 14:25 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198833
|
6.5 |
MEDIUM
Network
|
jenkins
|
pipeline_maven_integration
|
A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
|
CWE-863
Incorrect Authorization
|
CVE-2020-2233
|
2024-11-21 14:25 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198834
|
7.5 |
HIGH
Network
|
jenkins
|
email_extension
|
Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its exposure.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-2232
|
2024-11-21 14:25 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198835
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vuln…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2231
|
2024-11-21 14:25 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198836
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Ov…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2230
|
2024-11-21 14:25 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198837
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2229
|
2024-11-21 14:25 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198838
|
8.8 |
HIGH
Network
|
jenkins
|
gitlab_authentication
|
Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability.
|
CWE-863
Incorrect Authorization
|
CVE-2020-2228
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198839
|
5.4 |
MEDIUM
Network
|
jenkins
|
deployer_framework
|
Jenkins Deployer Framework Plugin 1.2 and earlier does not escape the URL displayed in the build home page, resulting in a stored cross-site scripting vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2227
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198840
|
5.4 |
MEDIUM
Network
|
jenkins
|
matrix_authorization_strategy
|
Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2226
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|