Vulnerabilities > Jenkins > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-16 CVE-2023-33003 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins TAG Profiler
A cross-site request forgery (CSRF) vulnerability in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers to reset profiler statistics.
network
low complexity
jenkins CWE-352
4.3
2023-05-16 CVE-2023-33004 Incorrect Permission Assignment for Critical Resource vulnerability in Jenkins TAG Profiler
A missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission to reset profiler statistics.
network
low complexity
jenkins CWE-732
4.3
2023-05-16 CVE-2023-33005 Insufficient Session Expiration vulnerability in Jenkins Wso2 Oauth
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.
network
low complexity
jenkins CWE-613
5.4
2023-05-16 CVE-2023-33006 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Wso2 Oauth
A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick users into logging in to the attacker's account.
network
low complexity
jenkins CWE-352
5.4
2023-05-16 CVE-2023-33007 Cross-site Scripting vulnerability in Jenkins Loadcomplete Support
Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
network
low complexity
jenkins CWE-79
5.4
2023-05-16 CVE-2023-32977 Cross-site Scripting vulnerability in Jenkins Pipeline: JOB
Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set build display names immediately.
network
low complexity
jenkins CWE-79
5.4
2023-05-16 CVE-2023-32978 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Lightweight Directory Access Protocol
A cross-site request forgery (CSRF) vulnerability in Jenkins LDAP Plugin allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials.
network
low complexity
jenkins CWE-352
4.3
2023-05-16 CVE-2023-32979 Incorrect Permission Assignment for Critical Resource vulnerability in Jenkins Email Extension
Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home directory on the controller file system.
network
low complexity
jenkins CWE-732
4.3
2023-05-16 CVE-2023-32980 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Email Extension
A cross-site request forgery (CSRF) vulnerability in Jenkins Email Extension Plugin allows attackers to make another user stop watching an attacker-specified job.
network
low complexity
jenkins CWE-352
4.3
2023-05-16 CVE-2023-32982 Missing Encryption of Sensitive Data vulnerability in Jenkins Ansible
Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier stores extra variables unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
network
low complexity
jenkins CWE-311
4.3