Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2020-11-04 CVE-2020-2307 Unspecified vulnerability in Jenkins Kubernetes
Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller environment variables.
network
low complexity
jenkins
4.3
2020-11-04 CVE-2020-2306 Unspecified vulnerability in Jenkins Mercurial
A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
network
low complexity
jenkins
4.3
2020-11-04 CVE-2020-2305 Unspecified vulnerability in Jenkins Mercurial
Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins
6.5
2020-11-04 CVE-2020-2304 Unspecified vulnerability in Jenkins Subversion
Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins
6.5
2020-11-04 CVE-2020-2303 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Active Directory
A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials.
network
low complexity
jenkins CWE-352
4.3
2020-11-04 CVE-2020-2302 Missing Authorization vulnerability in Jenkins Active Directory
A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page.
network
low complexity
jenkins CWE-862
4.3
2020-11-04 CVE-2020-2301 Unspecified vulnerability in Jenkins Active Directory
Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is still in the optional cache when using Windows/ADSI mode.
network
low complexity
jenkins
critical
9.8
2020-11-04 CVE-2020-2300 Unspecified vulnerability in Jenkins Active Directory
Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configuration of the Active Directory server.
network
low complexity
jenkins
critical
9.8
2020-11-04 CVE-2020-2299 Unspecified vulnerability in Jenkins Active Directory
Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.
network
low complexity
jenkins
critical
9.8
2020-10-08 CVE-2020-2296 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Shared Objects
A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to configure shared objects.
network
low complexity
jenkins CWE-352
4.3