Vulnerabilities > Jenkins > Beaker Builder > 1.4

DATE CVE VULNERABILITY TITLE RISK
2022-06-23 CVE-2022-34207 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Beaker Builder
A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specified URL.
network
low complexity
jenkins CWE-352
6.5
2022-06-23 CVE-2022-34208 Missing Authorization vulnerability in Jenkins Beaker Builder
A missing permission check in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
network
low complexity
jenkins CWE-862
4.3
2019-09-12 CVE-2019-10398 Insufficiently Protected Credentials vulnerability in Jenkins Beaker Builder
Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
local
low complexity
jenkins CWE-522
5.5