Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2023-43502

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to delete Failure Causes.
Attacker Value
Unknown

CVE-2023-43501

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.
Attacker Value
Unknown

CVE-2023-43500

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.
Attacker Value
Unknown

CVE-2023-43499

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or update Failure Causes.
Attacker Value
Unknown

CVE-2020-2244

Disclosure Date: September 01, 2020 (last updated February 22, 2025)
Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to provide console output for builds used to test build log indications.
Attacker Value
Unknown

CVE-2019-16553

Disclosure Date: December 17, 2019 (last updated October 26, 2023)
A cross-site request forgery vulnerability in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers to have Jenkins evaluate a computationally expensive regular expression.
Attacker Value
Unknown

CVE-2019-16555

Disclosure Date: December 17, 2019 (last updated October 26, 2023)
A user-supplied regular expression in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier was processed in a way that wasn't interruptible, allowing attackers to have Jenkins evaluate a regular expression without the ability to interrupt this process.
Attacker Value
Unknown

CVE-2019-16554

Disclosure Date: December 17, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Read permission to have Jenkins evaluate a computationally expensive regular expression.
Attacker Value
Unknown

CVE-2016-4988

Disclosure Date: February 09, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.
Attacker Value
Unknown

CVE-2013-6374

Disclosure Date: November 25, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0