Filtered by vendor Jenkins
Subscribe
Total
1647 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-2175 | 1 Jenkins | 1 Fitnesse | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control the XML input files processed by the plugin. | |||||
CVE-2020-2229 | 1 Jenkins | 1 Jenkins | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability. | |||||
CVE-2020-2206 | 1 Jenkins | 1 Vncrecorder | 2023-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
Jenkins VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability. | |||||
CVE-2020-2207 | 1 Jenkins | 1 Vncviewer | 2023-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
Jenkins VncViewer Plugin 1.7 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability. | |||||
CVE-2020-2236 | 1 Jenkins | 1 Yet Another Build Visualizer | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission. | |||||
CVE-2020-2243 | 1 Jenkins | 1 Cadence Vmanager | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission. | |||||
CVE-2020-2238 | 1 Jenkins | 1 Git Parameter | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. | |||||
CVE-2020-2231 | 1 Jenkins | 1 Jenkins | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token. | |||||
CVE-2020-2230 | 1 Jenkins | 1 Jenkins | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission. | |||||
CVE-2020-2244 | 1 Jenkins | 1 Build Failure Analyzer | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to provide console output for builds used to test build log indications. | |||||
CVE-2020-2248 | 1 Jenkins | 1 Jsgames | 2023-11-02 | 4.3 MEDIUM | 6.1 MEDIUM |
Jenkins JSGames Plugin 0.2 and earlier evaluates part of a URL as code, resulting in a reflected cross-site scripting (XSS) vulnerability. | |||||
CVE-2020-2246 | 1 Jenkins | 1 Valgrind | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Valgrind Plugin 0.28 and earlier does not escape content in Valgrind XML reports, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Valgrind XML report contents. | |||||
CVE-2019-10406 | 1 Jenkins | 1 Jenkins | 2023-11-02 | 3.5 LOW | 4.8 MEDIUM |
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global configuration, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission. | |||||
CVE-2019-10404 | 1 Jenkins | 1 Jenkins | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the reason why a queue items is blcoked in tooltips, resulting in a stored XSS vulnerability exploitable by users able to control parts of the reason a queue item is blocked, such as label expressions not matching any idle executors. | |||||
CVE-2019-10405 | 1 Jenkins | 1 Jenkins | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers exploiting another XSS vulnerability to obtain the HTTP session cookie despite it being marked HttpOnly. | |||||
CVE-2019-16562 | 1 Jenkins | 1 Buildgraph-view | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the description of builds shown in its view, resulting in a stored XSS vulnerability exploitable by users able to change build descriptions. | |||||
CVE-2020-2137 | 1 Jenkins | 1 Timestamper | 2023-11-02 | 3.5 LOW | 4.8 MEDIUM |
Jenkins Timestamper Plugin 1.11.1 and earlier does not sanitize HTML formatting of its output, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission. | |||||
CVE-2020-2106 | 1 Jenkins | 1 Code Coverage Api | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view, resulting in a stored XSS vulnerability exploitable by users able to change job configurations. | |||||
CVE-2019-16564 | 1 Jenkins | 1 Pipeline Aggregator View | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to affects view content such as job display name or pipeline stage names. | |||||
CVE-2019-16563 | 1 Jenkins | 1 Mission Control | 2023-11-02 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to change these properties. |