Vulnerabilities > Jenkins > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-11-04 CVE-2020-2309 Unspecified vulnerability in Jenkins Kubernetes
A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins
4.3
2020-11-04 CVE-2020-2308 Unspecified vulnerability in Jenkins Kubernetes
A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to list global pod template names.
network
low complexity
jenkins
4.3
2020-11-04 CVE-2020-2307 Unspecified vulnerability in Jenkins Kubernetes
Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller environment variables.
network
low complexity
jenkins
4.3
2020-11-04 CVE-2020-2306 Unspecified vulnerability in Jenkins Mercurial
A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
network
low complexity
jenkins
4.3
2020-11-04 CVE-2020-2305 Unspecified vulnerability in Jenkins Mercurial
Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins
6.5
2020-11-04 CVE-2020-2304 Unspecified vulnerability in Jenkins Subversion
Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins
6.5
2020-11-04 CVE-2020-2303 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Active Directory
A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials.
network
low complexity
jenkins CWE-352
4.3
2020-11-04 CVE-2020-2302 Missing Authorization vulnerability in Jenkins Active Directory
A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page.
network
low complexity
jenkins CWE-862
4.3
2020-10-08 CVE-2020-2296 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Shared Objects
A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to configure shared objects.
network
low complexity
jenkins CWE-352
4.3
2020-10-08 CVE-2020-2293 Unspecified vulnerability in Jenkins Persona
Jenkins Persona Plugin 2.4 and earlier allows users with Overall/Read permission to read arbitrary files on the Jenkins controller.
network
low complexity
jenkins
6.5