|
247921
|
6.5 |
MEDIUM
Network
|
agiletestware
|
pangolin_connector_for_testrail
|
A data modification vulnerability exists in Jenkins Agiletestware Pangolin Connector for TestRail Plugin 2.1 and earlier in GlobalConfig.java that allows attackers with Overall/Read permission to ove…
|
CWE-269
Improper Privilege Management
|
CVE-2018-1999032
|
2024-11-21 12:57 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247922
|
6.5 |
MEDIUM
Network
|
jenkins
|
meliora_testlab
|
An exposure of sensitive information vulnerability exists in Jenkins meliora-testlab Plugin 1.14 and earlier in TestlabNotifier.java that allows attackers with file system access to the Jenkins maste…
|
CWE-200
Information Exposure
|
CVE-2018-1999031
|
2024-11-21 12:57 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247923
|
5.4 |
MEDIUM
Network
|
jenkins
|
maven_artifact_choicelistprovider_\(nexus\)
|
An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and earlier in ArtifactoryChoiceListProvider.java, NexusChoiceListProvider.…
|
CWE-200
Information Exposure
|
CVE-2018-1999030
|
2024-11-21 12:57 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247924
|
5.4 |
MEDIUM
Network
|
jenkins
|
shelve_project
|
A cross-site scripting vulnerability exists in Jenkins Shelve Project Plugin 1.5 and earlier in ShelveProjectAction/index.jelly, ShelvedProjectsAction/index.jelly that allows attackers with Job/Confi…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1999029
|
2024-11-21 12:57 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247925
|
8.8 |
HIGH
Network
|
jenkins
|
accurev
|
An exposure of sensitive information vulnerability exists in Jenkins Accurev Plugin 0.7.16 and earlier in AccurevSCM.java that allows attackers to capture credentials with a known credentials ID stor…
|
CWE-200
Information Exposure
|
CVE-2018-1999028
|
2024-11-21 12:57 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247926
|
7.5 |
HIGH
Network
|
jenkins
|
saltstack
|
An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that allows attackers to capture credentials with a kn…
|
CWE-352
Origin Validation Error
|
CVE-2018-1999027
|
2024-11-21 12:57 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247927
|
6.5 |
MEDIUM
Network
|
jenkins
|
tracetronic_ecu-test
|
A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers to have Jenkins send HTTP requests to an attacker-…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-1999026
|
2024-11-21 12:57 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247928
|
7.4 |
HIGH
Network
|
jenkins
|
tracetronic_ecu-test
|
A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows attackers to impersonate any service that Jenkins c…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-1999025
|
2024-11-21 12:57 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247929
|
5.4 |
MEDIUM
Network
|
jenkins oracle
|
jenkins communications_cloud_native_core_automated_test_suite
|
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1999007
|
2024-11-21 12:57 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247930
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI fi…
|
CWE-200
Information Exposure
|
CVE-2018-1999006
|
2024-11-21 12:57 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|