|
199971
|
6.5 |
MEDIUM
Network
|
jenkins
|
pipeline_maven_integration
|
A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
|
CWE-863
Incorrect Authorization
|
CVE-2020-2233
|
2024-11-21 14:25 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199972
|
7.5 |
HIGH
Network
|
jenkins
|
email_extension
|
Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form, potentially resulting in its exposure.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-2232
|
2024-11-21 14:25 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199973
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vuln…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2231
|
2024-11-21 14:25 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199974
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Ov…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2230
|
2024-11-21 14:25 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199975
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2229
|
2024-11-21 14:25 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199976
|
8.8 |
HIGH
Network
|
jenkins
|
gitlab_authentication
|
Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulnerability.
|
CWE-863
Incorrect Authorization
|
CVE-2020-2228
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199977
|
5.4 |
MEDIUM
Network
|
jenkins
|
deployer_framework
|
Jenkins Deployer Framework Plugin 1.2 and earlier does not escape the URL displayed in the build home page, resulting in a stored cross-site scripting vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2227
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199978
|
5.4 |
MEDIUM
Network
|
jenkins
|
matrix_authorization_strategy
|
Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-2226
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199979
|
5.4 |
MEDIUM
Network
|
jenkins
|
matrix_project
|
Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerabi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2225
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199980
|
5.4 |
MEDIUM
Network
|
jenkins
|
matrix_project
|
Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site scripting vulnerabi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2224
|
2024-11-21 14:25 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|