Show filters
43 Total Results
Displaying 41-43 of 43
Sort by:
Attacker Value
Unknown

CVE-2024-28149

Disclosure Date: March 06, 2024 (last updated March 07, 2024)
Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.
0
Attacker Value
Unknown

CVE-2019-1003061

Disclosure Date: April 04, 2019 (last updated October 26, 2023)
Jenkins jenkins-cloudformation-plugin Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Attacker Value
Unknown

CVE-2013-5676

Disclosure Date: December 13, 2013 (last updated October 05, 2023)
The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.
0