Vulnerabilities > Jenkins > Debian Package Builder

DATE CVE VULNERABILITY TITLE RISK
2022-01-12 CVE-2022-23118 Exposure of Resource to Wrong Sphere vulnerability in Jenkins Debian Package Builder
Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller.
network
low complexity
jenkins CWE-668
8.8
2020-02-12 CVE-2020-2125 Insufficiently Protected Credentials vulnerability in Jenkins Debian Package Builder
Jenkins Debian Package Builder Plugin 1.6.11 and earlier stores a GPG passphrase unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-522
4.3