Vulnerabilities > Jenkins > Github Pull Request Builder > 1.41.0

DATE CVE VULNERABILITY TITLE RISK
2023-01-26 CVE-2023-24434 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Github Pull Request Builder
A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-352
8.8
2023-01-26 CVE-2023-24435 Missing Authorization vulnerability in Jenkins Github Pull Request Builder
A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
6.5
2023-01-26 CVE-2023-24436 Missing Authorization vulnerability in Jenkins Github Pull Request Builder
A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
4.3
2018-06-05 CVE-2018-1000186 Information Exposure vulnerability in Jenkins Github Pull Request Builder
A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-200
4.0