Vulnerabilities > Jenkins
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-16 | CVE-2023-32997 | Session Fixation vulnerability in Jenkins CAS Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login. | 8.8 |
2023-05-16 | CVE-2023-32998 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Appspider A cross-site request forgery (CSRF) vulnerability in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers to connect to an attacker-specified URL and send an HTTP POST request with a JSON payload consisting of attacker-specified credentials. | 8.8 |
2023-05-16 | CVE-2023-32999 | Incorrect Default Permissions vulnerability in Jenkins Appspider A missing permission check in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL and send an HTTP POST request with a JSON payload consisting of attacker-specified credentials. | 4.3 |
2023-05-16 | CVE-2023-33000 | Insufficiently Protected Credentials vulnerability in Jenkins Ns-Nd Integration Performance Publisher Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them. | 7.5 |
2023-05-16 | CVE-2023-33001 | Information Exposure Through Log Files vulnerability in Jenkins Hashicorp Vault Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled. | 7.5 |
2023-05-16 | CVE-2023-33002 | Cross-site Scripting vulnerability in Jenkins Testcomplete Support Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | 5.4 |
2023-05-16 | CVE-2023-33003 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins TAG Profiler A cross-site request forgery (CSRF) vulnerability in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers to reset profiler statistics. | 4.3 |
2023-05-16 | CVE-2023-33004 | Incorrect Permission Assignment for Critical Resource vulnerability in Jenkins TAG Profiler A missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission to reset profiler statistics. | 4.3 |
2023-05-16 | CVE-2023-33005 | Insufficient Session Expiration vulnerability in Jenkins Wso2 Oauth 1.0 Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login. | 5.4 |
2023-05-16 | CVE-2023-33006 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Wso2 Oauth A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick users into logging in to the attacker's account. | 5.4 |