Vulnerabilities > Jenkins > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-10-16 CVE-2019-10457 Missing Authorization vulnerability in Jenkins Oracle Cloud Infrastructure Compute Classic 1.0.0
A missing permission check in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
network
low complexity
jenkins CWE-862
4.3
2019-10-16 CVE-2019-10456 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Oracle Cloud Infrastructure Compute Classic 1.0.0
A cross-site request forgery vulnerability in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
network
low complexity
jenkins CWE-352
4.3
2019-10-16 CVE-2019-10455 Missing Authorization vulnerability in Jenkins Rundeck
A missing permission check in Jenkins Rundeck Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
network
low complexity
jenkins CWE-862
4.3
2019-10-16 CVE-2019-10454 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Rundeck
A cross-site request forgery vulnerability in Jenkins Rundeck Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
network
low complexity
jenkins CWE-352
4.3
2019-10-16 CVE-2019-10452 Cleartext Storage of Sensitive Information vulnerability in Jenkins View26 Test-Reporting
Jenkins View26 Test-Reporting Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-312
4.3
2019-10-16 CVE-2019-10451 Cleartext Storage of Sensitive Information vulnerability in Jenkins Soasta Cloudtest
Jenkins SOASTA CloudTest Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-312
4.3
2019-10-16 CVE-2019-10447 Cleartext Storage of Sensitive Information vulnerability in Jenkins Sofy.Ai 1.0.0/1.0.1/1.0.3
Jenkins Sofy.AI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-312
4.3
2019-10-16 CVE-2019-10445 Missing Authorization vulnerability in Jenkins Google Kubernetes Engine
A missing permission check in Jenkins Google Kubernetes Engine Plugin 0.7.0 and earlier allowed attackers with Overall/Read permission to obtain limited information about the scope of a credential with an attacker-specified credentials ID.
network
low complexity
jenkins CWE-862
4.3
2019-10-16 CVE-2019-10444 Improper Certificate Validation vulnerability in Jenkins Bumblebee HP ALM
Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connections to HP ALM.
network
low complexity
jenkins CWE-295
6.5
2019-10-16 CVE-2019-10442 Missing Authorization vulnerability in Jenkins Icescrum
A missing permission check in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
network
low complexity
jenkins CWE-862
4.3