Show filters
288 Total Results
Displaying 21-30 of 288
Sort by:
Attacker Value
Unknown
CVE-2024-52550
Disclosure Date: November 13, 2024 (last updated November 14, 2024)
Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.
0
Attacker Value
Unknown
CVE-2024-52549
Disclosure Date: November 13, 2024 (last updated November 14, 2024)
Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files on the controller file system.
0
Attacker Value
Unknown
CVE-2024-47807
Disclosure Date: October 02, 2024 (last updated October 03, 2024)
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.
0
Attacker Value
Unknown
CVE-2024-47806
Disclosure Date: October 02, 2024 (last updated October 03, 2024)
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.
0
Attacker Value
Unknown
CVE-2024-47804
Disclosure Date: October 02, 2024 (last updated November 14, 2024)
If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates the item in memory, only deleting it from disk, allowing attackers with Item/Configure permission to save the item to persist it, effectively bypassing the item creation restriction.
0
Attacker Value
Unknown
CVE-2024-47803
Disclosure Date: October 02, 2024 (last updated November 14, 2024)
Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form field.
0
Attacker Value
Unknown
CVE-2024-43045
Disclosure Date: August 07, 2024 (last updated August 17, 2024)
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to access other users' "My Views".
0
Attacker Value
Unknown
CVE-2024-39460
Disclosure Date: June 26, 2024 (last updated June 27, 2024)
Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.
0
Attacker Value
Unknown
CVE-2024-39459
Disclosure Date: June 26, 2024 (last updated June 27, 2024)
In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global credentials) or with Item/Extended Read permission (folder-scoped credentials).
0
Attacker Value
Unknown
CVE-2024-39458
Disclosure Date: June 26, 2024 (last updated June 27, 2024)
When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message containing diagnostic information that may contain secrets passed as step parameters, potentially resulting in accidental exposure of secrets through the default system log.
0