Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2022-0839

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.
Attacker Value
Unknown

CVE-2020-2285

Disclosure Date: September 23, 2020 (last updated February 22, 2025)
A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2020-2284

Disclosure Date: September 23, 2020 (last updated February 22, 2025)
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Attacker Value
Unknown

CVE-2020-2283

Disclosure Date: September 23, 2020 (last updated February 22, 2025)
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control changeset files evaluated by the plugin.
Attacker Value
Unknown

CVE-2018-1000146

Disclosure Date: April 05, 2018 (last updated November 26, 2024)
An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.
0