Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown
CVE-2021-28472
Disclosure Date: April 13, 2021 (last updated November 28, 2024)
Visual Studio Code Maven for Java Extension Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2021-26719
Disclosure Date: February 09, 2021 (last updated November 28, 2024)
A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can perform a registration step such that crafted TAR archives lead to extraction of files into arbitrary filesystem locations.
0
Attacker Value
Unknown
CVE-2020-10721
Disclosure Date: October 22, 2020 (last updated November 28, 2024)
A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configuration file on the local machine executing the maven plug-in could allow for deserialization of untrusted data resulting in arbitrary code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
0
Attacker Value
Unknown
CVE-2020-2295
Disclosure Date: October 08, 2020 (last updated October 26, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Maven Cascade Release Plugin 1.3.2 and earlier allows attackers to start cascade builds and layout builds, and reconfigure the plugin.
0
Attacker Value
Unknown
CVE-2020-2294
Disclosure Date: October 08, 2020 (last updated October 26, 2023)
Jenkins Maven Cascade Release Plugin 1.3.2 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to start cascade builds and layout builds, and reconfigure the plugin.
0
Attacker Value
Unknown
CVE-2020-2256
Disclosure Date: September 16, 2020 (last updated October 26, 2023)
Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
0
Attacker Value
Unknown
CVE-2020-15777
Disclosure Date: August 25, 2020 (last updated November 28, 2024)
An issue was discovered in the Maven Extension plugin before 1.6 for Gradle Enterprise. The extension uses a socket connection to send serialized Java objects. Deserialization is not restricted to an allow-list, thus allowing an attacker to achieve code execution via a malicious deserialization gadget chain. The socket is not bound exclusively to localhost. The port this socket is assigned to is randomly selected and is not intentionally exposed to the public (either by design or documentation). This could potentially be used to achieve remote code execution and local privilege escalation.
0
Attacker Value
Unknown
CVE-2020-2235
Disclosure Date: August 12, 2020 (last updated October 07, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows attackers to connect to an attacker-specified JDBC URL using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2020-2234
Disclosure Date: August 12, 2020 (last updated October 07, 2023)
A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to connect to an attacker-specified JDBC URL using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2020-2233
Disclosure Date: August 12, 2020 (last updated October 07, 2023)
A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
0