Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-2208 1 Jenkins 1 Slack Upload 2024-11-21 4.3 Medium
Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
CVE-2019-1003044 1 Jenkins 1 Slack Notification 2024-11-21 N/A
A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2019-1003043 1 Jenkins 1 Slack Notification 2024-11-21 7.5 High
A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.