Vulnerabilities > Jenkins > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-11-04 CVE-2020-2312 Unspecified vulnerability in Jenkins Sqlplus Script Runner
Jenkins SQLPlus Script Runner Plugin 2.0.12 and earlier does not mask a password provided as command line argument in build logs.
network
low complexity
jenkins
6.5
2020-11-04 CVE-2020-2311 Unspecified vulnerability in Jenkins AWS Global Configuration
A missing permission check in Jenkins AWS Global Configuration Plugin 1.5 and earlier allows attackers with Overall/Read permission to replace the global AWS configuration.
network
low complexity
jenkins
4.3
2020-11-04 CVE-2020-2310 Unspecified vulnerability in Jenkins Ansible
Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins
4.3
2020-11-04 CVE-2020-2309 Unspecified vulnerability in Jenkins Kubernetes
A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins
4.3
2020-11-04 CVE-2020-2308 Unspecified vulnerability in Jenkins Kubernetes
A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to list global pod template names.
network
low complexity
jenkins
4.3
2020-11-04 CVE-2020-2307 Unspecified vulnerability in Jenkins Kubernetes
Jenkins Kubernetes Plugin 1.27.3 and earlier allows low-privilege users to access possibly sensitive Jenkins controller environment variables.
network
low complexity
jenkins
4.3
2020-11-04 CVE-2020-2306 Unspecified vulnerability in Jenkins Mercurial
A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
network
low complexity
jenkins
4.3
2020-11-04 CVE-2020-2305 Unspecified vulnerability in Jenkins Mercurial
Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins
6.5
2020-11-04 CVE-2020-2304 Unspecified vulnerability in Jenkins Subversion
Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins
6.5
2020-11-04 CVE-2020-2303 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Active Directory
A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials.
network
low complexity
jenkins CWE-352
4.3