Show filters
288 Total Results
Displaying 121-130 of 288
Sort by:
Attacker Value
Unknown
CVE-2020-2101
Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.
0
Attacker Value
Unknown
CVE-2020-2104
Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.
0
Attacker Value
Unknown
CVE-2020-2102
Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
0
Attacker Value
Unknown
CVE-2020-2100
Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848.
0
Attacker Value
Unknown
CVE-2020-2103
Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
0
Attacker Value
Unknown
CVE-2020-2105
Disclosure Date: January 29, 2020 (last updated February 21, 2025)
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
0
Attacker Value
Unknown
CVE-2019-16544
Disclosure Date: November 21, 2019 (last updated October 26, 2023)
Jenkins QMetry for JIRA - Test Management Plugin 1.12 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
0
Attacker Value
Unknown
CVE-2019-16545
Disclosure Date: November 21, 2019 (last updated October 26, 2023)
Jenkins QMetry for JIRA - Test Management Plugin transmits credentials in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.
0
Attacker Value
Unknown
CVE-2012-4440
Disclosure Date: November 18, 2019 (last updated November 27, 2024)
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.
0
Attacker Value
Unknown
CVE-2012-4441
Disclosure Date: November 18, 2019 (last updated November 27, 2024)
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.
0