Show filters
1,655 Total Results
Displaying 141-150 of 1,655
Sort by:
Attacker Value
Unknown
CVE-2023-3442
Disclosure Date: July 26, 2023 (last updated October 08, 2023)
A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform.
0
Attacker Value
Unknown
CVE-2023-3414
Disclosure Date: July 26, 2023 (last updated October 08, 2023)
A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform.
0
Attacker Value
Unknown
CVE-2023-39156
Disclosure Date: July 26, 2023 (last updated October 08, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Bazaar Plugin 1.22 and earlier allows attackers to delete previously created Bazaar SCM tags.
0
Attacker Value
Unknown
CVE-2023-39155
Disclosure Date: July 26, 2023 (last updated October 08, 2023)
Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.
0
Attacker Value
Unknown
CVE-2023-39154
Disclosure Date: July 26, 2023 (last updated October 08, 2023)
Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with global Item/Configure permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2023-39153
Disclosure Date: July 26, 2023 (last updated October 08, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to the attacker's account.
0
Attacker Value
Unknown
CVE-2023-39152
Disclosure Date: July 26, 2023 (last updated October 08, 2023)
Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i.e., replaced with asterisks) in the build log in some circumstances.
0
Attacker Value
Unknown
CVE-2023-39151
Disclosure Date: July 26, 2023 (last updated October 08, 2023)
Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.
0
Attacker Value
Unknown
CVE-2023-37965
Disclosure Date: July 12, 2023 (last updated October 08, 2023)
A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2023-37964
Disclosure Date: July 12, 2023 (last updated October 08, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
0