Filtered by vendor Jenkins
Subscriptions
Total
1606 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2019-1010241 | 1 Jenkins | 1 Credentials Binding | 2024-08-05 | 6.5 Medium |
Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly line #30 (passwordVariable). The attack vector is: Attacker creates and executes a Jenkins job. | ||||
CVE-2019-1003035 | 1 Jenkins | 1 Azure Vm Agents | 2024-08-05 | 4.3 Medium |
An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgentTemplate.java, src/main/java/com/microsoft/azure/vmagent/AzureVMCloud.java that allows attackers with Overall/Read permission to perform the 'verify configuration' form validation action, thereby obtaining limited information about the Azure configuration. | ||||
CVE-2019-1003097 | 1 Jenkins | 1 Crowd Integration | 2024-08-05 | 6.5 Medium |
Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | ||||
CVE-2019-1003098 | 1 Jenkins | 1 Openid | 2024-08-05 | N/A |
A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server. | ||||
CVE-2019-1003085 | 1 Jenkins | 1 Zephyr Enterprise Test Management | 2024-08-05 | 6.5 Medium |
A missing permission check in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | ||||
CVE-2019-1003087 | 1 Jenkins | 1 Chef Sinatra | 2024-08-05 | 6.5 Medium |
A missing permission check in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | ||||
CVE-2019-1003094 | 1 Jenkins | 1 Open Stf | 2024-08-05 | 6.5 Medium |
Jenkins Open STF Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | ||||
CVE-2019-1003079 | 1 Jenkins | 1 Vmware Lab Manager Slaves | 2024-08-05 | 6.5 Medium |
A missing permission check in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | ||||
CVE-2019-1003096 | 1 Jenkins | 1 Testfairy | 2024-08-05 | 6.5 Medium |
Jenkins TestFairy Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | ||||
CVE-2019-1003091 | 1 Jenkins | 1 Soasta Cloudtest | 2024-08-05 | 6.5 Medium |
A missing permission check in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | ||||
CVE-2019-1003083 | 1 Jenkins | 1 Gearman | 2024-08-05 | 6.5 Medium |
A missing permission check in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | ||||
CVE-2019-1003049 | 3 Jenkins, Oracle, Redhat | 4 Jenkins, Communications Cloud Native Core Automated Test Suite, Openshift and 1 more | 2024-08-05 | 8.1 High |
Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches. | ||||
CVE-2019-1003084 | 1 Jenkins | 1 Zephyr Enterprise Test Management | 2024-08-05 | N/A |
A cross-site request forgery vulnerability in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server. | ||||
CVE-2019-1003081 | 1 Jenkins | 1 Openshift Deployer | 2024-08-05 | 6.5 Medium |
A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | ||||
CVE-2019-1003088 | 1 Jenkins | 1 Fabric Beta Publisher | 2024-08-05 | 6.5 Medium |
Jenkins Fabric Beta Publisher Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | ||||
CVE-2019-1003092 | 1 Jenkins | 1 Nomad | 2024-08-05 | N/A |
A cross-site request forgery vulnerability in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server. | ||||
CVE-2019-1003043 | 1 Jenkins | 1 Slack Notification | 2024-08-05 | 7.5 High |
A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | ||||
CVE-2019-1003093 | 1 Jenkins | 1 Nomad | 2024-08-05 | 6.5 Medium |
A missing permission check in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | ||||
CVE-2019-1003099 | 1 Jenkins | 1 Openid | 2024-08-05 | 6.5 Medium |
A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | ||||
CVE-2019-1003047 | 1 Jenkins | 1 Fortify On Demand Uploader | 2024-08-05 | 6.5 Medium |
A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. |