|
223401
|
8.8 |
HIGH
Network
|
jenkins
|
team_concert
|
A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained …
|
CWE-352
Origin Validation Error
|
CVE-2019-16565
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223402
|
5.4 |
MEDIUM
Network
|
jenkins
|
pipeline_aggregator_view
|
Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to affects view content su…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16564
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223403
|
5.4 |
MEDIUM
Network
|
jenkins
|
mission_control
|
Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to change …
|
CWE-79
Cross-site Scripting
|
CVE-2019-16563
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223404
|
5.4 |
MEDIUM
Network
|
jenkins
|
buildgraph-view
|
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the description of builds shown in its view, resulting in a stored XSS vulnerability exploitable by users able to change build descripti…
|
CWE-79
Cross-site Scripting
|
CVE-2019-16562
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223405
|
7.1 |
HIGH
Network
|
jenkins
|
websphere_deployer
|
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for the entire Jenkins master JVM.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-16561
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223406
|
8.8 |
HIGH
Network
|
jenkins
|
websphere_deployer
|
A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to perform connection tests and determine whether files with an attacker-specified p…
|
CWE-352
Origin Validation Error
|
CVE-2019-16560
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223407
|
5.4 |
MEDIUM
Network
|
jenkins
|
websphere_deployer
|
A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection tests and determine whether files with an attacke…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16559
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223408
|
8.2 |
HIGH
Network
|
jenkins
|
spira_importer
|
Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-16558
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223409
|
6.5 |
MEDIUM
Network
|
jenkins
|
redgate_sql_change_automation
|
Jenkins Redgate SQL Change Automation Plugin 2.0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permis…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-16557
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223410
|
6.5 |
MEDIUM
Network
|
jenkins
|
rundeck
|
Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Exten…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-16556
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|