Latest CVE Feed
-
6.5
MEDIUMCVE-2018-1000421
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-specified credent... Read more
Affected Products : mesos- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-1000420
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.... Read more
Affected Products : mesos- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-1000419
An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.... Read more
Affected Products : hipchat- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-1000418
An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attacker-specified cr... Read more
Affected Products : hipchat- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-1000417
A cross-site request forgery vulnerability exists in Jenkins Email Extension Template Plugin 1.0 and earlier in ExtEmailTemplateManagement.java that allows creating or removing templates.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-1000416
A reflected cross-site scripting vulnerability exists in Jenkins Job Config History Plugin 2.18 and earlier in all Jelly files that shows arbitrary attacker-specified HTML in Jenkins to users with Job/Configure access.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1000415
A cross-site scripting vulnerability exists in Jenkins Rebuilder Plugin 1.28 and earlier in RebuildAction/BooleanParameterValue.jelly, RebuildAction/ExtendedChoiceParameterValue.jelly, RebuildAction/FileParameterValue.jelly, RebuildAction/LabelParameterVa... Read more
Affected Products : rebuild- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-1000414
A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigFileAction.java that allows creating and editing configuration file definitions.... Read more
Affected Products : config_file_provider- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-1000413
A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jen... Read more
Affected Products : config_file_provider- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-1000412
An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to an attacker-specified URL using attacker-specified credentials IDs obtained ... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-1000411
A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of a test result.... Read more
Affected Products : junit- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-1000410
An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/model/Descriptor.ja... Read more
Affected Products : jenkins- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2018-1000409
A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing session and creating a new one when a... Read more
Affected Products : jenkins- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-1000408
A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instance... Read more
Affected Products : jenkins- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-1000407
A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by J... Read more
Affected Products : jenkins- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-1000406
A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permission to define a file parameter with a file name outside ... Read more
Affected Products : jenkins- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-1000404
Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFactory.java, CodeBuilder.java that can result in Credentials Disclosure. This attack appear to be exploitable ... Read more
Affected Products : aws_codebuild- Published: Jul. 09, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-1000403
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result in Credentials Disclosure. This attack appear to be exploitable via local f... Read more
Affected Products : aws_codedeploy- Published: Jul. 09, 2018
- Modified: Nov. 21, 2024
-
5.0
MEDIUMCVE-2018-1000402
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposure vulnerability in AWSCodeDeployPublisher.java that can result in Disclosure of environment variables. This vulnerability appears to ha... Read more
Affected Products : aws_codedeploy- Published: Jul. 09, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-1000401
Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipelineSCM.java that can result in Credentials Disclosure. This attack appear to be exploitable via local fil... Read more
Affected Products : aws_codepipeline- Published: Jul. 09, 2018
- Modified: Nov. 21, 2024