Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2022-34208

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
A missing permission check in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
Attacker Value
Unknown

CVE-2022-34207

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specified URL.
Attacker Value
Unknown

CVE-2013-7489

Disclosure Date: June 26, 2020 (last updated February 21, 2025)
The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2020-12079

Disclosure Date: April 23, 2020 (last updated February 21, 2025)
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron internal messaging API.
Attacker Value
Unknown

CVE-2019-10398

Disclosure Date: September 12, 2019 (last updated October 26, 2023)
Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Attacker Value
Unknown

CVE-2015-3160

Disclosure Date: September 06, 2017 (last updated November 26, 2024)
XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to obtain sensitive information via submitting job XML to the server containing entity references which reference files from the Beaker server's file system.
0
Attacker Value
Unknown

CVE-2015-3163

Disclosure Date: September 06, 2017 (last updated November 26, 2024)
The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote authenticated users to modify power types and key types via navigating to $BEAKER/powertypes and $BEAKER/keytypes respectively.
Attacker Value
Unknown

CVE-2015-3161

Disclosure Date: September 06, 2017 (last updated November 26, 2024)
The search bar code in bkr/server/widgets.py in Beaker before 20.1 does not escape </script> tags in string literals when producing JSON.
0
Attacker Value
Unknown

CVE-2015-3162

Disclosure Date: September 06, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the edit comment dialog in bkr/server/widgets.py in Beaker 20.1 allows remote authenticated users to inject arbitrary web script or HTML via writing a crafted comment on an acked or nacked canceled job.
0
Attacker Value
Unknown

CVE-2012-3458

Disclosure Date: September 15, 2012 (last updated October 05, 2023)
Beaker before 1.6.4, when using PyCrypto to encrypt sessions, uses AES in ECB cipher mode, which might allow remote attackers to obtain portions of sensitive session data via unspecified vectors.
0