Vulnerabilities > Jenkins > Warnings > 5.0.1

DATE CVE VULNERABILITY TITLE RISK
2023-10-25 CVE-2023-46651 Insufficiently Protected Credentials vulnerability in Jenkins Warnings
Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
network
low complexity
jenkins CWE-522
6.5
2020-09-23 CVE-2020-2280 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Warnings
A cross-site request forgery (CSRF) vulnerability in Jenkins Warnings Plugin 5.0.1 and earlier allows attackers to execute arbitrary code.
network
low complexity
jenkins CWE-352
8.8