Show filters
39 Total Results
Displaying 1-10 of 39
Sort by:
Attacker Value
Unknown
CVE-2023-44487
Disclosure Date: October 10, 2023 (last updated June 28, 2024)
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
1
Attacker Value
Unknown
CVE-2025-24403
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
A missing permission check in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of Azure credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2025-24402
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers to connect to a Service Fabric URL using attacker-specified credentials IDs obtained through another method.
0
Attacker Value
Unknown
CVE-2025-24401
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.
0
Attacker Value
Unknown
CVE-2025-24400
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event published to RabbitMQ with the legitimate credentials.
0
Attacker Value
Unknown
CVE-2025-24399
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in letter case, potentially gaining administrator access to Jenkins.
0
Attacker Value
Unknown
CVE-2025-24398
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
0
Attacker Value
Unknown
CVE-2025-24397
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2024-54004
Disclosure Date: November 27, 2024 (last updated December 21, 2024)
Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2024-54003
Disclosure Date: November 27, 2024 (last updated December 21, 2024)
Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Create permission.
0