Latest CVE Feed
-
4.3
MEDIUMCVE-2021-21661
Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : kubernetes- EPSS Score: %0.30
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-21660
Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to edit any description rendered using the configured ... Read more
Affected Products : markdown_formatter- EPSS Score: %0.25
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-21659
Jenkins URLTrigger Plugin 0.48 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.... Read more
Affected Products : urltrigger- EPSS Score: %1.22
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-21658
Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.... Read more
Affected Products : nuget- EPSS Score: %0.38
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21657
Jenkins Filesystem Trigger Plugin 0.40 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.... Read more
Affected Products : filesystem_trigger- EPSS Score: %0.16
- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-21656
Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.... Read more
Affected Products : xcode_integration- EPSS Score: %0.11
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-21655
A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified Perforce server using attacker-specified username and password.... Read more
Affected Products : p4- EPSS Score: %0.09
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21654
Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified Perforce server using attacker-specified username and password.... Read more
Affected Products : p4- EPSS Score: %0.05
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21653
Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier does not perform a permission check in an HTTP endpoint, allowing with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : xray_-_test_management_for_jira- EPSS Score: %0.06
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-21652
A cross-site request forgery (CSRF) vulnerability in Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, captur... Read more
Affected Products : xray_-_test_management_for_jira- EPSS Score: %0.10
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21651
Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain the list of configured profiles.... Read more
Affected Products : s3_publisher- EPSS Score: %0.06
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21650
Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform Run/Artifacts permission checks in various HTTP endpoints and API models, allowing attackers with Item/Read permission to obtain information about artifacts uploaded to S3, if the optional Ru... Read more
Affected Products : s3_publisher- EPSS Score: %0.05
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-21649
Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.... Read more
Affected Products : dashboard_view- EPSS Score: %0.98
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-21648
Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulting in a reflected cross-site scripting (XSS) vulnerability.... Read more
Affected Products : credentials- EPSS Score: %0.11
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21647
Jenkins CloudBees CD Plugin 1.1.21 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Item/Read permission to schedule builds of projects without having Item/Build permission.... Read more
Affected Products : cloudbees_cd- EPSS Score: %0.09
- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21646
Jenkins Templating Engine Plugin 2.1 and earlier does not protect its pipeline configurations using Script Security Plugin, allowing attackers with Job/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.... Read more
Affected Products : templating_engine- EPSS Score: %0.39
- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21645
Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs.... Read more
Affected Products : config_file_provider- EPSS Score: %0.12
- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-21644
A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID.... Read more
Affected Products : config_file_provider- EPSS Score: %0.07
- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-21643
Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenki... Read more
Affected Products : config_file_provider- EPSS Score: %0.46
- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-21642
Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.... Read more
Affected Products : config_file_provider- EPSS Score: %1.00
- Published: Apr. 21, 2021
- Modified: Nov. 21, 2024