Show filters
1,655 Total Results
Displaying 21-30 of 1,655
Sort by:
Attacker Value
Unknown
CVE-2024-47807
Disclosure Date: October 02, 2024 (last updated October 03, 2024)
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.
0
Attacker Value
Unknown
CVE-2024-47806
Disclosure Date: October 02, 2024 (last updated October 03, 2024)
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.
0
Attacker Value
Unknown
CVE-2024-47805
Disclosure Date: October 02, 2024 (last updated November 14, 2024)
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.
0
Attacker Value
Unknown
CVE-2024-47804
Disclosure Date: October 02, 2024 (last updated November 14, 2024)
If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates the item in memory, only deleting it from disk, allowing attackers with Item/Configure permission to save the item to persist it, effectively bypassing the item creation restriction.
0
Attacker Value
Unknown
CVE-2024-47803
Disclosure Date: October 02, 2024 (last updated November 14, 2024)
Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form field.
0
Attacker Value
Unknown
CVE-2024-43045
Disclosure Date: August 07, 2024 (last updated August 17, 2024)
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to access other users' "My Views".
0
Attacker Value
Unknown
CVE-2024-39460
Disclosure Date: June 26, 2024 (last updated June 27, 2024)
Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of the Bitbucket URL in the build log in some cases.
0
Attacker Value
Unknown
CVE-2024-39459
Disclosure Date: June 26, 2024 (last updated June 27, 2024)
In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global credentials) or with Item/Extended Read permission (folder-scoped credentials).
0
Attacker Value
Unknown
CVE-2024-39458
Disclosure Date: June 26, 2024 (last updated June 27, 2024)
When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message containing diagnostic information that may contain secrets passed as step parameters, potentially resulting in accidental exposure of secrets through the default system log.
0
Attacker Value
Unknown
CVE-2024-5273
Disclosure Date: May 24, 2024 (last updated May 25, 2024)
Jenkins Report Info Plugin 1.2 and earlier does not perform path validation of the workspace directory while serving report files, allowing attackers with Item/Configure permission to retrieve Surefire failures, PMD violations, Findbugs bugs, and Checkstyle errors on the controller file system by editing the workspace path.
0