Show filters
288 Total Results
Displaying 261-270 of 288
Sort by:
Attacker Value
Unknown

CVE-2013-7330

Disclosure Date: October 17, 2014 (last updated October 05, 2023)
Jenkins before 1.502 allows remote authenticated users to configure an otherwise restricted project via vectors related to post-build actions.
0
Attacker Value
Unknown

CVE-2014-2064

Disclosure Date: October 17, 2014 (last updated October 05, 2023)
The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.
0
Attacker Value
Unknown

CVE-2014-3661

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI handshake.
0
Attacker Value
Unknown

CVE-2014-3680

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.
0
Attacker Value
Unknown

CVE-2014-3667

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.
0
Attacker Value
Unknown

CVE-2014-3662

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts.
0
Attacker Value
Unknown

CVE-2014-3666

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel.
0
Attacker Value
Unknown

CVE-2014-3663

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and create or destroy arbitrary jobs via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-3681

Disclosure Date: October 15, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-3664

Disclosure Date: October 15, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Overall/READ permission to read arbitrary files via unspecified vectors.
0