Show filters
288 Total Results
Displaying 171-180 of 288
Sort by:
Attacker Value
Unknown

CVE-2018-1999003

Disclosure Date: July 23, 2018 (last updated November 27, 2024)
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.
Attacker Value
Unknown

CVE-2018-1999004

Disclosure Date: July 23, 2018 (last updated November 27, 2024)
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches.
Attacker Value
Unknown

CVE-2018-1999001

Disclosure Date: July 23, 2018 (last updated November 27, 2024)
A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from the Jenkins home directory. If Jenkins is started without this file present, it will revert to the legacy defaults of granting administrator access to anonymous users.
Attacker Value
Unknown

CVE-2018-1999002

Disclosure Date: July 23, 2018 (last updated November 27, 2024)
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master has access to.
Attacker Value
Unknown

CVE-2018-1000195

Disclosure Date: June 05, 2018 (last updated November 26, 2024)
A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn whether the response is successful (200) or not.
Attacker Value
Unknown

CVE-2018-1000194

Disclosure Date: June 05, 2018 (last updated November 26, 2024)
A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.
Attacker Value
Unknown

CVE-2018-1000192

Disclosure Date: June 05, 2018 (last updated November 26, 2024)
A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.
Attacker Value
Unknown

CVE-2018-1000193

Disclosure Date: June 05, 2018 (last updated November 26, 2024)
A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the UI.
Attacker Value
Unknown

CVE-2017-2598

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).
0
Attacker Value
Unknown

CVE-2017-2609

Disclosure Date: May 22, 2018 (last updated November 26, 2024)
jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autocomplete feature on the search box discloses the names of the views in its suggestions, including the ones for which the current user does not have access to.
0