Show filters
288 Total Results
Displaying 151-160 of 288
Sort by:
Attacker Value
Unknown
CVE-2019-1003004
Disclosure Date: January 22, 2019 (last updated October 26, 2023)
An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration of active HTTP sessions indefinitely even though the user account may have been deleted in the mean time.
0
Attacker Value
Unknown
CVE-2019-1003003
Disclosure Date: January 22, 2019 (last updated October 26, 2023)
An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, allowing e.g. to persist access to temporarily compromised user accounts.
0
Attacker Value
Unknown
CVE-2018-1000408
Disclosure Date: January 09, 2019 (last updated November 27, 2024)
A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in Jenkins user database security realm that results in the creation of an ephemeral user record in memory.
0
Attacker Value
Unknown
CVE-2018-1000407
Disclosure Date: January 09, 2019 (last updated November 27, 2024)
A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by Jenkins.
0
Attacker Value
Unknown
CVE-2018-1000409
Disclosure Date: January 09, 2019 (last updated November 27, 2024)
A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing session and creating a new one when a user signed up for a new user account.
0
Attacker Value
Unknown
CVE-2018-1000410
Disclosure Date: January 09, 2019 (last updated November 27, 2024)
An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/model/Descriptor.java that allows attackers with Overall/Administer permission or access to the local file system to obtain credentials entered by users if the form submission could not be successfully processed.
0
Attacker Value
Unknown
CVE-2018-1000406
Disclosure Date: January 09, 2019 (last updated November 27, 2024)
A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.
0
Attacker Value
Unknown
CVE-2018-1000864
Disclosure Date: December 10, 2018 (last updated November 27, 2024)
A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
0
Attacker Value
Unknown
CVE-2018-1000862
Disclosure Date: December 10, 2018 (last updated November 27, 2024)
An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build using the workspace browser.
0
Attacker Value
Unknown
CVE-2018-1000863
Disclosure Date: December 10, 2018 (last updated November 27, 2024)
A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim from logging into Jenkins.
0