Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2022-34208
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
A missing permission check in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
0
Attacker Value
Unknown
CVE-2022-34207
Disclosure Date: June 23, 2022 (last updated February 23, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specified URL.
0
Attacker Value
Unknown
CVE-2013-7489
Disclosure Date: June 26, 2020 (last updated February 21, 2025)
The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2020-12079
Disclosure Date: April 23, 2020 (last updated February 21, 2025)
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron internal messaging API.
0
Attacker Value
Unknown
CVE-2019-10398
Disclosure Date: September 12, 2019 (last updated October 26, 2023)
Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
0
Attacker Value
Unknown
CVE-2015-3160
Disclosure Date: September 06, 2017 (last updated November 26, 2024)
XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing entity references which reference files from the Beaker server's file system.
0
Attacker Value
Unknown
CVE-2015-3163
Disclosure Date: September 06, 2017 (last updated November 26, 2024)
The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote authenticated users to modify power types and key types via navigating to $BEAKER/powertypes and $BEAKER/keytypes respectively.
0
Attacker Value
Unknown
CVE-2015-3161
Disclosure Date: September 06, 2017 (last updated November 26, 2024)
The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals when producing JSON.
0
Attacker Value
Unknown
CVE-2015-3162
Disclosure Date: September 06, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the edit comment dialog in bkr/server/widgets.py in Beaker 20.1 allows remote authenticated users to inject arbitrary web script or HTML via writing a crafted comment on an acked or nacked canceled job.
0
Attacker Value
Unknown
CVE-2012-3458
Disclosure Date: September 15, 2012 (last updated October 05, 2023)
Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.
0