Vulnerabilities > Jenkins > Inedo Buildmaster > 1.2

DATE CVE VULNERABILITY TITLE RISK
2019-09-25 CVE-2019-10411 Cleartext Transmission of Sensitive Information vulnerability in Jenkins Inedo Buildmaster
Jenkins Inedo BuildMaster Plugin 2.4.0 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
network
low complexity
jenkins CWE-319
7.5
2018-08-01 CVE-2018-1999035 Improper Certificate Validation vulnerability in Jenkins Inedo Buildmaster 1.0/1.2/1.3
A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java, BuildMasterApi.java that allows attackers to impersonate any service that Jenkins connects to.
network
jenkins CWE-295
5.8