Show filters
39 Total Results
Displaying 1-10 of 39
Sort by:
Attacker Value
Unknown

CVE-2023-44487

Disclosure Date: October 10, 2023 (last updated June 28, 2024)
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Attacker Value
Unknown

CVE-2025-24403

Disclosure Date: January 22, 2025 (last updated January 23, 2025)
A missing permission check in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of Azure credentials stored in Jenkins.
0
Attacker Value
Unknown

CVE-2025-24402

Disclosure Date: January 22, 2025 (last updated January 23, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers to connect to a Service Fabric URL using attacker-specified credentials IDs obtained through another method.
0
Attacker Value
Unknown

CVE-2025-24401

Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.
0
Attacker Value
Unknown

CVE-2025-24400

Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event published to RabbitMQ with the legitimate credentials.
0
Attacker Value
Unknown

CVE-2025-24399

Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in letter case, potentially gaining administrator access to Jenkins.
0
Attacker Value
Unknown

CVE-2025-24398

Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
0
Attacker Value
Unknown

CVE-2025-24397

Disclosure Date: January 22, 2025 (last updated January 23, 2025)
An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.
0
Attacker Value
Unknown

CVE-2024-54004

Disclosure Date: November 27, 2024 (last updated December 21, 2024)
Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.
0
Attacker Value
Unknown

CVE-2024-54003

Disclosure Date: November 27, 2024 (last updated December 21, 2024)
Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Create permission.
0