Show filters
288 Total Results
Displaying 161-170 of 288
Sort by:
Attacker Value
Unknown
CVE-2018-1000861
Disclosure Date: December 10, 2018 (last updated November 27, 2024)
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.
0
Attacker Value
Unknown
CVE-2018-1999042
Disclosure Date: August 23, 2018 (last updated November 27, 2024)
A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.
0
Attacker Value
Unknown
CVE-2018-1999047
Disclosure Date: August 23, 2018 (last updated November 27, 2024)
A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.
0
Attacker Value
Unknown
CVE-2018-1999045
Disclosure Date: August 23, 2018 (last updated November 27, 2024)
A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2.java that allows attackers with a valid cookie to remain logged in even if that feature is disabled.
0
Attacker Value
Unknown
CVE-2018-1999044
Disclosure Date: August 23, 2018 (last updated November 27, 2024)
A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
0
Attacker Value
Unknown
CVE-2018-1999046
Disclosure Date: August 23, 2018 (last updated November 27, 2024)
A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.java that allows attackers With Overall/Read permission to access the connection log for any agent.
0
Attacker Value
Unknown
CVE-2018-1999043
Disclosure Date: August 23, 2018 (last updated November 27, 2024)
A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows attackers to create ephemeral in-memory user records by attempting to log in using invalid credentials.
0
Attacker Value
Unknown
CVE-2018-1999007
Disclosure Date: July 23, 2018 (last updated November 27, 2024)
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would be executed in another user's browser when that other user views HTTP 404 error pages while Stapler debug mode is enabled.
0
Attacker Value
Unknown
CVE-2018-1999006
Disclosure Date: July 23, 2018 (last updated November 27, 2024)
A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of the most recent installation/upgrade.
0
Attacker Value
Unknown
CVE-2018-1999005
Disclosure Date: July 23, 2018 (last updated November 27, 2024)
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
0