Vulnerabilities > Jenkins > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-04-04 CVE-2019-10290 Missing Authorization vulnerability in Jenkins Netsparker Cloud Scan
A missing permission check in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI form validation method allowed attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-862
6.5
2019-04-04 CVE-2019-10289 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Netsparker Cloud Scan
A cross-site request forgery vulnerability in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI form validation method allowed attackers to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-352
6.5
2019-04-04 CVE-2019-10279 Missing Authorization vulnerability in Jenkins Jenkins-Reviewbot
A missing permission check in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-862
6.5
2019-04-04 CVE-2019-10278 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Jenkins-Reviewbot
A cross-site request forgery vulnerability in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-352
6.5
2019-04-04 CVE-2019-1003099 Missing Authorization vulnerability in Jenkins Openid
A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-862
6.5
2019-04-04 CVE-2019-1003098 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Openid
A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-352
6.5
2019-04-04 CVE-2019-1003097 Insufficiently Protected Credentials vulnerability in Jenkins Crowd Integration 1.0/1.1/1.2
Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2019-04-04 CVE-2019-1003096 Insufficiently Protected Credentials vulnerability in Jenkins Testfairy
Jenkins TestFairy Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2019-04-04 CVE-2019-1003095 Missing Encryption of Sensitive Data vulnerability in Jenkins Perfecto Mobile
Jenkins Perfecto Mobile Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-311
6.5
2019-04-04 CVE-2019-1003094 Missing Encryption of Sensitive Data vulnerability in Jenkins Open STF
Jenkins Open STF Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-311
6.5