Show filters
288 Total Results
Displaying 41-50 of 288
Sort by:
Attacker Value
Unknown
CVE-2024-28161
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled by default.
0
Attacker Value
Unknown
CVE-2024-28160
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
0
Attacker Value
Unknown
CVE-2024-28159
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build.
0
Attacker Value
Unknown
CVE-2024-28158
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger a build.
0
Attacker Value
Unknown
CVE-2024-28157
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
0
Attacker Value
Unknown
CVE-2024-28152
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when using Bitbucket Server.
0
Attacker Value
Unknown
CVE-2024-28151
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with Item/Configure permission to determine whether a path on the Jenkins controller file system exists, without being able to access it.
0
Attacker Value
Unknown
CVE-2024-28150
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
0
Attacker Value
Unknown
CVE-2024-28149
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.
0
Attacker Value
Unknown
CVE-2024-23898
Disclosure Date: January 24, 2024 (last updated February 01, 2024)
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.
0