Vulnerabilities > Jenkins
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-11-04 | CVE-2020-2307 | Unspecified vulnerability in Jenkins Kubernetes Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller environment variables. | 4.3 |
2020-11-04 | CVE-2020-2306 | Unspecified vulnerability in Jenkins Mercurial A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations. | 4.3 |
2020-11-04 | CVE-2020-2305 | Unspecified vulnerability in Jenkins Mercurial Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | 6.5 |
2020-11-04 | CVE-2020-2304 | Unspecified vulnerability in Jenkins Subversion Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | 6.5 |
2020-11-04 | CVE-2020-2303 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Active Directory A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials. | 4.3 |
2020-11-04 | CVE-2020-2302 | Missing Authorization vulnerability in Jenkins Active Directory A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page. | 4.3 |
2020-11-04 | CVE-2020-2301 | Unspecified vulnerability in Jenkins Active Directory Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is still in the optional cache when using Windows/ADSI mode. | 9.8 |
2020-11-04 | CVE-2020-2300 | Unspecified vulnerability in Jenkins Active Directory Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configuration of the Active Directory server. | 9.8 |
2020-11-04 | CVE-2020-2299 | Unspecified vulnerability in Jenkins Active Directory Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password. | 9.8 |
2020-10-08 | CVE-2020-2296 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Shared Objects A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to configure shared objects. | 4.3 |