|
199661
|
5.3 |
MEDIUM
Network
|
sensiolabs fedoraproject
|
symfony fedora
|
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling de…
|
-
|
CVE-2021-21424
|
2024-11-21 14:48 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199662
|
7.1 |
HIGH
Network
|
jenkins
|
xcode_integration
|
Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
-
|
CVE-2021-21656
|
2024-11-21 14:48 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199663
|
7.1 |
HIGH
Network
|
jenkins
|
p4
|
A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified Perforce server using attacker-specified username and pa…
|
CWE-352
Origin Validation Error
|
CVE-2021-21655
|
2024-11-21 14:48 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199664
|
4.3 |
MEDIUM
Network
|
jenkins
|
p4
|
Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified Perforce server…
|
-
|
CVE-2021-21654
|
2024-11-21 14:48 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199665
|
4.3 |
MEDIUM
Network
|
jenkins
|
xray_-_test_management_for_jira
|
Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier does not perform a permission check in an HTTP endpoint, allowing with Overall/Read permission to enumerate credentials IDs of credent…
|
-
|
CVE-2021-21653
|
2024-11-21 14:48 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199666
|
7.1 |
HIGH
Network
|
jenkins
|
xray_-_test_management_for_jira
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified…
|
CWE-352
Origin Validation Error
|
CVE-2021-21652
|
2024-11-21 14:48 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199667
|
4.3 |
MEDIUM
Network
|
jenkins
|
s3_publisher
|
Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain the list of configured profiles.
|
-
|
CVE-2021-21651
|
2024-11-21 14:48 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199668
|
4.3 |
MEDIUM
Network
|
jenkins
|
s3_publisher
|
Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform Run/Artifacts permission checks in various HTTP endpoints and API models, allowing attackers with Item/Read permission to obtain inform…
|
-
|
CVE-2021-21650
|
2024-11-21 14:48 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199669
|
5.4 |
MEDIUM
Network
|
jenkins
|
dashboard_view
|
Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers wit…
|
CWE-79
Cross-site Scripting
|
CVE-2021-21649
|
2024-11-21 14:48 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199670
|
6.1 |
MEDIUM
Network
|
jenkins
|
credentials
|
Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulting in a reflected cross-site scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2021-21648
|
2024-11-21 14:48 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|