Show filters
1,655 Total Results
Displaying 31-40 of 1,655
Sort by:
Attacker Value
Unknown
CVE-2024-34148
Disclosure Date: May 02, 2024 (last updated May 03, 2024)
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefinedParameters'.
0
Attacker Value
Unknown
CVE-2024-34147
Disclosure Date: May 02, 2024 (last updated May 03, 2024)
Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2024-34146
Disclosure Date: May 02, 2024 (last updated May 03, 2024)
Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing attackers with a previously configured SSH public key but lacking Overall/Read permission to access these repositories.
0
Attacker Value
Unknown
CVE-2024-34145
Disclosure Date: May 02, 2024 (last updated May 03, 2024)
A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
0
Attacker Value
Unknown
CVE-2024-34144
Disclosure Date: May 02, 2024 (last updated May 03, 2024)
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
0
Attacker Value
Unknown
CVE-2024-2216
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.
0
Attacker Value
Unknown
CVE-2024-2215
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.
0
Attacker Value
Unknown
CVE-2024-28162
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections fails to take effect until Jenkins is restarted when switching from disabled validation to enabled validation.
0
Attacker Value
Unknown
CVE-2024-28161
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled by default.
0
Attacker Value
Unknown
CVE-2024-28160
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
0