Vulnerabilities > Jenkins > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-04-04 | CVE-2019-10290 | Missing Authorization vulnerability in Jenkins Netsparker Cloud Scan A missing permission check in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI form validation method allowed attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-10289 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Netsparker Cloud Scan A cross-site request forgery vulnerability in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI form validation method allowed attackers to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-10279 | Missing Authorization vulnerability in Jenkins Jenkins-Reviewbot A missing permission check in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-10278 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Jenkins-Reviewbot A cross-site request forgery vulnerability in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-1003099 | Missing Authorization vulnerability in Jenkins Openid A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-1003098 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Openid A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-1003097 | Insufficiently Protected Credentials vulnerability in Jenkins Crowd Integration 1.0/1.1/1.2 Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | 6.5 |
2019-04-04 | CVE-2019-1003096 | Insufficiently Protected Credentials vulnerability in Jenkins Testfairy Jenkins TestFairy Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | 6.5 |
2019-04-04 | CVE-2019-1003095 | Missing Encryption of Sensitive Data vulnerability in Jenkins Perfecto Mobile Jenkins Perfecto Mobile Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | 6.5 |
2019-04-04 | CVE-2019-1003094 | Missing Encryption of Sensitive Data vulnerability in Jenkins Open STF Jenkins Open STF Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | 6.5 |