Vulnerabilities > Jenkins > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-04-04 CVE-2019-10279 Missing Authorization vulnerability in Jenkins Jenkins-Reviewbot
A missing permission check in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-862
6.5
2019-04-04 CVE-2019-10278 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Jenkins-Reviewbot
A cross-site request forgery vulnerability in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-352
6.5
2019-04-04 CVE-2019-1003099 Missing Authorization vulnerability in Jenkins Openid
A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-862
6.5
2019-04-04 CVE-2019-1003098 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Openid
A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-352
6.5
2019-04-04 CVE-2019-1003097 Insufficiently Protected Credentials vulnerability in Jenkins Crowd Integration 1.0/1.1/1.2
Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2019-04-04 CVE-2019-1003096 Insufficiently Protected Credentials vulnerability in Jenkins Testfairy
Jenkins TestFairy Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2019-04-04 CVE-2019-1003095 Missing Encryption of Sensitive Data vulnerability in Jenkins Perfecto Mobile
Jenkins Perfecto Mobile Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-311
6.5
2019-04-04 CVE-2019-1003094 Missing Encryption of Sensitive Data vulnerability in Jenkins Open STF
Jenkins Open STF Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-311
6.5
2019-04-04 CVE-2019-1003093 Missing Authorization vulnerability in Jenkins Nomad
A missing permission check in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-862
6.5
2019-04-04 CVE-2019-1003092 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Nomad
A cross-site request forgery vulnerability in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-352
6.5