Show filters
39 Total Results
Displaying 21-30 of 39
Sort by:
Attacker Value
Unknown

CVE-2024-39458

Disclosure Date: June 26, 2024 (last updated June 27, 2024)
When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message containing diagnostic information that may contain secrets passed as step parameters, potentially resulting in accidental exposure of secrets through the default system log.
0
Attacker Value
Unknown

CVE-2024-5273

Disclosure Date: May 24, 2024 (last updated May 25, 2024)
Jenkins Report Info Plugin 1.2 and earlier does not perform path validation of the workspace directory while serving report files, allowing attackers with Item/Configure permission to retrieve Surefire failures, PMD violations, Findbugs bugs, and Checkstyle errors on the controller file system by editing the workspace path.
0
Attacker Value
Unknown

CVE-2024-34148

Disclosure Date: May 02, 2024 (last updated May 03, 2024)
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefinedParameters'.
0
Attacker Value
Unknown

CVE-2024-34147

Disclosure Date: May 02, 2024 (last updated May 03, 2024)
Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
0
Attacker Value
Unknown

CVE-2024-34146

Disclosure Date: May 02, 2024 (last updated May 03, 2024)
Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing attackers with a previously configured SSH public key but lacking Overall/Read permission to access these repositories.
0
Attacker Value
Unknown

CVE-2024-34145

Disclosure Date: May 02, 2024 (last updated May 03, 2024)
A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
0
Attacker Value
Unknown

CVE-2024-34144

Disclosure Date: May 02, 2024 (last updated May 03, 2024)
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
0
Attacker Value
Unknown

CVE-2024-2216

Disclosure Date: March 06, 2024 (last updated March 07, 2024)
A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.
0
Attacker Value
Unknown

CVE-2024-2215

Disclosure Date: March 06, 2024 (last updated March 07, 2024)
A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.
0
Attacker Value
Unknown

CVE-2024-28162

Disclosure Date: March 06, 2024 (last updated March 07, 2024)
In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections fails to take effect until Jenkins is restarted when switching from disabled validation to enabled validation.
0