|
200241
|
5.4 |
MEDIUM
Network
|
jenkins
|
findbugs
|
Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide r…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2317
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200242
|
5.4 |
MEDIUM
Network
|
jenkins
|
static_analysis_utilities
|
Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2316
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200243
|
6.5 |
MEDIUM
Network
|
jenkins
|
visualworks_store
|
Jenkins Visualworks Store Plugin 1.1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2020-2315
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200244
|
5.5 |
MEDIUM
Local
|
jenkins
|
appspider
|
Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins control…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-2314
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200245
|
4.3 |
MEDIUM
Network
|
jenkins
|
azure_key_vault
|
A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
|
-
|
CVE-2020-2313
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200246
|
6.5 |
MEDIUM
Network
|
jenkins
|
sqlplus_script_runner
|
Jenkins SQLPlus Script Runner Plugin 2.0.12 and earlier does not mask a password provided as command line argument in build logs.
|
-
|
CVE-2020-2312
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200247
|
4.3 |
MEDIUM
Network
|
jenkins
|
aws_global_configuration
|
A missing permission check in Jenkins AWS Global Configuration Plugin 1.5 and earlier allows attackers with Overall/Read permission to replace the global AWS configuration.
|
-
|
CVE-2020-2311
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200248
|
4.3 |
MEDIUM
Network
|
jenkins
|
ansible
|
Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
|
-
|
CVE-2020-2310
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200249
|
4.3 |
MEDIUM
Network
|
jenkins
|
kubernetes
|
A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
|
-
|
CVE-2020-2309
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200250
|
4.3 |
MEDIUM
Network
|
jenkins
|
kubernetes
|
A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to list global pod template names.
|
-
|
CVE-2020-2308
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|