Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown

CVE-2024-47805

Disclosure Date: October 02, 2024 (last updated November 14, 2024)
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.
Attacker Value
Unknown

CVE-2024-39459

Disclosure Date: June 26, 2024 (last updated June 27, 2024)
In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global credentials) or with Item/Extended Read permission (folder-scoped credentials).
0
Attacker Value
Unknown

CVE-2023-25768

Disclosure Date: February 15, 2023 (last updated October 08, 2023)
A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server.
Attacker Value
Unknown

CVE-2023-25767

Disclosure Date: February 15, 2023 (last updated October 08, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers to connect to an attacker-specified web server.
Attacker Value
Unknown

CVE-2023-25766

Disclosure Date: February 15, 2023 (last updated October 08, 2023)
A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2023-24425

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled to.
Attacker Value
Unknown

CVE-2022-29036

Disclosure Date: April 12, 2022 (last updated October 25, 2023)
Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Attacker Value
Unknown

CVE-2022-27199

Disclosure Date: March 15, 2022 (last updated October 25, 2023)
A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token.
Attacker Value
Unknown

CVE-2022-27198

Disclosure Date: March 15, 2022 (last updated October 25, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token.
Attacker Value
Unknown

CVE-2022-20616

Disclosure Date: January 12, 2022 (last updated October 25, 2023)
Jenkins Credentials Binding Plugin 1.27 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read access to validate if a credential ID refers to a secret file credential and whether it's a zip file.