Show filters
288 Total Results
Displaying 141-150 of 288
Sort by:
Attacker Value
Unknown
CVE-2019-10352
Disclosure Date: July 17, 2019 (last updated October 26, 2023)
A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.
0
Attacker Value
Unknown
CVE-2019-10354
Disclosure Date: July 17, 2019 (last updated October 26, 2023)
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
0
Attacker Value
Unknown
CVE-2019-10353
Disclosure Date: July 17, 2019 (last updated October 26, 2023)
CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.
0
Attacker Value
Unknown
CVE-2019-11350
Disclosure Date: April 19, 2019 (last updated November 27, 2024)
CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the proxy configuration page.
0
Attacker Value
Unknown
CVE-2019-1003049
Disclosure Date: April 10, 2019 (last updated October 26, 2023)
Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.
0
Attacker Value
Unknown
CVE-2019-1003050
Disclosure Date: April 10, 2019 (last updated October 26, 2023)
The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.
0
Attacker Value
Unknown
CVE-2019-1003061
Disclosure Date: April 04, 2019 (last updated October 26, 2023)
Jenkins jenkins-cloudformation-plugin Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
0
Attacker Value
Unknown
CVE-2019-10278
Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A cross-site request forgery vulnerability in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
0
Attacker Value
Unknown
CVE-2019-10279
Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
0
Attacker Value
Unknown
CVE-2018-1000997
Disclosure Date: January 23, 2019 (last updated November 27, 2024)
A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/org/kohsuke/stapler/Facet.java, groovy/src/main/java/org/kohsuke/stapler/jelly/groovy/GroovyFacet.java, jelly/src/main/java/org/kohsuke/stapler/jelly/JellyFacet.java, jruby/src/main/java/org/kohsuke/stapler/jelly/jruby/JRubyFacet.java, jsp/src/main/java/org/kohsuke/stapler/jsp/JSPFacet.java that allows attackers to render routable objects using any view in Jenkins, exposing internal information about those objects not intended to be viewed, such as their toString() representation.
0