Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2023-07-12 CVE-2023-37944 Missing Authorization vulnerability in Jenkins Datadog
A missing permission check in Jenkins Datadog Plugin 5.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
6.5
2023-07-12 CVE-2023-37945 Missing Authorization vulnerability in Jenkins Saml Single Sign on 2.1.0/2.2.0/2.3.0
A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attackers with Overall/Read permission to download a string representation of the current security realm.
network
low complexity
jenkins CWE-862
4.3
2023-07-12 CVE-2023-37946 Session Fixation vulnerability in Jenkins Openshift Login
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login.
network
low complexity
jenkins CWE-384
8.8
2023-07-12 CVE-2023-37947 Open Redirect vulnerability in Jenkins Openshift Login
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
network
low complexity
jenkins CWE-601
6.1
2023-07-12 CVE-2023-37948 Improper Input Validation vulnerability in Jenkins Cloud Infrastructure Compute
Jenkins Oracle Cloud Infrastructure Compute Plugin 1.0.16 and earlier does not validate SSH host keys when connecting OCI clouds, enabling man-in-the-middle attacks.
network
high complexity
jenkins CWE-20
3.7
2023-07-12 CVE-2023-37949 Missing Authorization vulnerability in Jenkins Orka BY Macstadium
A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
7.1
2023-07-12 CVE-2023-37950 Missing Authorization vulnerability in Jenkins Mabl
A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
4.3
2023-07-12 CVE-2023-37951 Insufficiently Protected Credentials vulnerability in Jenkins Mabl
Jenkins mabl Plugin 0.0.46 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
network
low complexity
jenkins CWE-522
6.5
2023-07-12 CVE-2023-37952 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Mabl
A cross-site request forgery (CSRF) vulnerability in Jenkins mabl Plugin 0.0.46 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-352
6.5
2023-07-12 CVE-2023-37953 Missing Authorization vulnerability in Jenkins Mabl
A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
6.5