|
199131
|
9.8 |
CRITICAL
Network
|
jenkins
|
active_directory
|
Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.
|
-
|
CVE-2020-2299
|
2024-11-21 14:25 |
2020-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199132
|
6.5 |
MEDIUM
Network
|
jenkins
|
nerrvana
|
Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2020-2298
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199133
|
3.3 |
LOW
Local
|
jenkins
|
sms_notification
|
Jenkins SMS Notification Plugin 1.2 and earlier stores an access token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkin…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-2297
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199134
|
4.3 |
MEDIUM
Network
|
jenkins
|
shared_objects
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to configure shared objects.
|
CWE-352
Origin Validation Error
|
CVE-2020-2296
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199135
|
6.5 |
MEDIUM
Network
|
barchart
|
maven_cascade_release
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attackers to start cascade builds and layout builds, and reconfigure the plugin.
|
CWE-352
Origin Validation Error
|
CVE-2020-2295
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199136
|
6.5 |
MEDIUM
Network
|
barchart
|
maven_cascade_release
|
Jenkins Maven Cascade Release Plugin 1.3.2 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to start cascade builds and layout…
|
-
|
CVE-2020-2294
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199137
|
6.5 |
MEDIUM
Network
|
jenkins
|
persona
|
Jenkins Persona Plugin 2.4 and earlier allows users with Overall/Read permission to read arbitrary files on the Jenkins controller.
|
-
|
CVE-2020-2293
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199138
|
5.4 |
MEDIUM
Network
|
jenkins
|
release
|
Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Release/Re…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2292
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199139
|
3.3 |
LOW
Local
|
jenkins
|
couchdb-statistics
|
Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-2291
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199140
|
5.4 |
MEDIUM
Network
|
jenkins
|
active_choices
|
Jenkins Active Choices Plugin 2.4 and earlier does not escape some return values of sandboxed scripts for Reactive Reference Parameters, resulting in a stored cross-site scripting (XSS) vulnerability…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2290
|
2024-11-21 14:25 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|