Show filters
65 Total Results
Displaying 51-60 of 65
Sort by:
Attacker Value
Unknown
CVE-2020-2118
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2019-10315
Disclosure Date: April 30, 2019 (last updated October 26, 2023)
Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent CSRF.
0
Attacker Value
Unknown
CVE-2017-18365
Disclosure Date: March 28, 2019 (last updated November 27, 2024)
The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated remote attackers to execute arbitrary code. This occurs because the enterprise session secret is always the same, and can be found in the product's source code. By sending a crafted cookie signed with this secret, one can call Marshal.load with arbitrary data, which is a problem because the Marshal data format allows Ruby objects.
0
Attacker Value
Unknown
CVE-2019-1003018
Disclosure Date: February 06, 2019 (last updated October 26, 2023)
An exposure of sensitive information vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious extension) to retrieve the configured client secret.
0
Attacker Value
Unknown
CVE-2019-1003019
Disclosure Date: February 06, 2019 (last updated October 26, 2023)
An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.
0
Attacker Value
Unknown
CVE-2018-1000600
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2018-1000184
Disclosure Date: June 05, 2018 (last updated November 26, 2024)
A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
0
Attacker Value
Unknown
CVE-2018-1000186
Disclosure Date: June 05, 2018 (last updated November 26, 2024)
A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2018-1000183
Disclosure Date: June 05, 2018 (last updated November 26, 2024)
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2018-1000185
Disclosure Date: June 05, 2018 (last updated November 26, 2024)
A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
0