Vulnerabilities > Jenkins > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-04-04 | CVE-2019-1003083 | Missing Authorization vulnerability in Jenkins Gearman A missing permission check in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-1003082 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Gearman A cross-site request forgery vulnerability in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-1003081 | Missing Authorization vulnerability in Jenkins Openshift Deployer A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-1003080 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Openshift Deployer A cross-site request forgery vulnerability in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-1003079 | Missing Authorization vulnerability in Jenkins VMWare LAB Manager Slaves A missing permission check in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-1003078 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins VMWare LAB Manager Slaves A cross-site request forgery vulnerability in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-1003077 | Missing Authorization vulnerability in Jenkins Audit to Database A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-1003076 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Audit to Database A cross-site request forgery vulnerability in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-1003059 | Missing Authorization vulnerability in Jenkins FTP Publisher A missing permission check in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | 6.5 |
2019-04-04 | CVE-2019-1003058 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins FTP Publisher A cross-site request forgery vulnerability in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers to initiate a connection to an attacker-specified server. | 6.5 |