Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2022-0839
Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.
0
Attacker Value
Unknown
CVE-2020-2285
Disclosure Date: September 23, 2020 (last updated February 22, 2025)
A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2020-2284
Disclosure Date: September 23, 2020 (last updated February 22, 2025)
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
0
Attacker Value
Unknown
CVE-2020-2283
Disclosure Date: September 23, 2020 (last updated February 22, 2025)
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control changeset files evaluated by the plugin.
0
Attacker Value
Unknown
CVE-2018-1000146
Disclosure Date: April 05, 2018 (last updated November 26, 2024)
An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.
0