|
222421
|
8.8 |
HIGH
Network
|
jenkins
|
websphere_deployer
|
A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to perform connection tests and determine whether files with an attacker-specified p…
|
CWE-352
Origin Validation Error
|
CVE-2019-16560
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222422
|
5.4 |
MEDIUM
Network
|
jenkins
|
websphere_deployer
|
A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection tests and determine whether files with an attacke…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16559
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222423
|
8.2 |
HIGH
Network
|
jenkins
|
spira_importer
|
Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.
|
CWE-295
Improper Certificate Validation
|
CVE-2019-16558
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222424
|
6.5 |
MEDIUM
Network
|
jenkins
|
redgate_sql_change_automation
|
Jenkins Redgate SQL Change Automation Plugin 2.0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permis…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-16557
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222425
|
6.5 |
MEDIUM
Network
|
jenkins
|
rundeck
|
Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Exten…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-16556
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222426
|
6.5 |
MEDIUM
Network
|
jenkins
|
build_failure_analyzer
|
A user-supplied regular expression in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier was processed in a way that wasn't interruptible, allowing attackers to have Jenkins evaluate a regular …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-16555
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222427
|
4.3 |
MEDIUM
Network
|
jenkins
|
build_failure_analyzer
|
A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Read permission to have Jenkins evaluate a computationally expensive regular expre…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16554
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222428
|
8.8 |
HIGH
Network
|
jenkins
|
build_failure_analyzer
|
A cross-site request forgery vulnerability in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers to have Jenkins evaluate a computationally expensive regular expression.
|
CWE-352
Origin Validation Error
|
CVE-2019-16553
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222429
|
5.4 |
MEDIUM
Network
|
jenkins
|
gerrit_trigger
|
A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL or SSH server using attacker-…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16552
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222430
|
8.8 |
HIGH
Network
|
jenkins
|
gerrit_trigger
|
A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers to connect to an attacker-specified HTTP URL or SSH server using attacker-specified cre…
|
CWE-352
Origin Validation Error
|
CVE-2019-16551
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|