|
257051
|
5.9 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-1000396
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257052
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.73.1 and earlier, 2.83 and earlier provides information about Jenkins user accounts which is generally available to anyone with Overall/Read permissions via the /user/(username)/api remote …
|
CWE-200
Information Exposure
|
CVE-2017-1000395
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257053
|
7.5 |
HIGH
Network
|
jenkins
|
jenkins
|
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has be…
|
CWE-20
Improper Input Validation
|
CVE-2017-1000394
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257054
|
8.8 |
HIGH
Network
|
jenkins
|
jenkins
|
Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could configure a launch method called 'Launch agent via execution of command on master'. T…
|
CWE-78
OS Command
|
CVE-2017-1000393
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257055
|
4.8 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000392
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257056
|
7.3 |
HIGH
Network
|
jenkins
|
jenkins
|
Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual user accounts, as well as users appearing in SCM, in directories corresponding t…
|
CWE-20
Improper Input Validation
|
CVE-2017-1000391
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257057
|
4.3 |
MEDIUM
Network
|
jenkins
|
multijob
|
Jenkins Multijob plugin version 1.25 and earlier did not check permissions in the Resume Build action, allowing anyone with Job/Read permission to resume the build.
|
CWE-862
Missing Authorization
|
CVE-2017-1000390
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257058
|
4.3 |
MEDIUM
Network
|
jenkins
|
dependency_graph_viewer
|
Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modifies the dependency graph, allowing anyone with Overall/Read permission to modi…
|
CWE-862
Missing Authorization
|
CVE-2017-1000388
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257059
|
6.1 |
MEDIUM
Network
|
jenkins
|
global-build-stats
|
Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could h…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000389
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257060
|
7.8 |
HIGH
Local
|
jenkins
|
build-publisher
|
Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home director…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-1000387
|
2024-11-21 12:04 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|