Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2023-12-13 CVE-2023-50775 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Deployment Dashboard
A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to copy jobs.
network
low complexity
jenkins CWE-352
4.3
2023-12-13 CVE-2023-50776 Cleartext Storage of Sensitive Information vulnerability in Jenkins Paaslane Estimate 1.0.4
Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
network
low complexity
jenkins CWE-312
4.3
2023-12-13 CVE-2023-50777 Cleartext Storage of Sensitive Information vulnerability in Jenkins Paaslane Estimate 1.0.4
Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
network
low complexity
jenkins CWE-312
4.3
2023-12-13 CVE-2023-50778 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Paaslane Estimate 1.0.4
A cross-site request forgery (CSRF) vulnerability in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified token.
network
low complexity
jenkins CWE-352
8.8
2023-12-13 CVE-2023-50779 Missing Authorization vulnerability in Jenkins Paaslane Estimate 1.0.4
Missing permission checks in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified token.
network
low complexity
jenkins CWE-862
4.3
2023-11-29 CVE-2023-49652 Missing Authorization vulnerability in Jenkins Google Compute Engine
Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate system-scoped credentials IDs of credentials stored in Jenkins and to connect to Google Cloud Platform using attacker-specified credentials IDs obtained through another method, to obtain information about existing projects.
network
low complexity
jenkins CWE-862
2.7
2023-11-29 CVE-2023-49653 Insufficiently Protected Credentials vulnerability in Jenkins Jira
Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
network
low complexity
jenkins CWE-522
6.5
2023-11-29 CVE-2023-49654 Missing Authorization vulnerability in Jenkins Matlab
Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system.
network
low complexity
jenkins CWE-862
critical
9.8
2023-11-29 CVE-2023-49655 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Matlab
A cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11.0 and earlier allows attackers to have Jenkins parse an XML file from the Jenkins controller file system.
network
low complexity
jenkins CWE-352
8.8
2023-11-29 CVE-2023-49656 XXE vulnerability in Jenkins Matlab
Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
critical
9.8