Lucene search

K

Credentials Security Vulnerabilities

cve
cve

CVE-2024-39459

In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global credentials) or with...

6.8AI Score

0.0004EPSS

2024-06-26 05:15 PM
12
cve
cve

CVE-2023-25767

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers to connect to an attacker-specified web...

8.8CVSS

8.6AI Score

0.001EPSS

2023-02-15 02:15 PM
42
cve
cve

CVE-2023-25768

A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web...

6.5CVSS

6.3AI Score

0.001EPSS

2023-02-15 02:15 PM
41
cve
cve

CVE-2023-25766

A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in...

4.3CVSS

4.4AI Score

0.001EPSS

2023-02-15 02:15 PM
35
cve
cve

CVE-2023-24425

Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Kubernetes credentials they are not entitled...

6.5CVSS

6.3AI Score

0.001EPSS

2023-01-26 09:18 PM
31
cve
cve

CVE-2018-1000601

A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file...

6.5CVSS

6.2AI Score

0.001EPSS

2022-10-03 04:21 PM
41
cve
cve

CVE-2022-29036

Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability...

5.4CVSS

5.2AI Score

0.001EPSS

2022-04-12 08:15 PM
146
cve
cve

CVE-2022-27198

A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified...

8CVSS

7.7AI Score

0.001EPSS

2022-03-15 05:15 PM
121
cve
cve

CVE-2022-27199

A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified...

4.3CVSS

4.7AI Score

0.001EPSS

2022-03-15 05:15 PM
84
cve
cve

CVE-2022-20616

Jenkins Credentials Binding Plugin 1.27 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read access to validate if a credential ID refers to a secret file credential and whether it's a zip...

4.3CVSS

4.3AI Score

0.001EPSS

2022-01-12 08:15 PM
91
cve
cve

CVE-2021-21648

Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulting in a reflected cross-site scripting (XSS)...

6.1CVSS

5.8AI Score

0.001EPSS

2021-05-11 03:15 PM
78
2
cve
cve

CVE-2021-21625

Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins in some...

4.3CVSS

4.8AI Score

0.001EPSS

2021-03-18 02:15 PM
42
cve
cve

CVE-2020-2181

Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build...

6.5CVSS

6.2AI Score

0.001EPSS

2020-05-06 01:15 PM
98
cve
cve

CVE-2020-2182

Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a $ character in some...

4.3CVSS

4.3AI Score

0.001EPSS

2020-05-06 01:15 PM
95
cve
cve

CVE-2019-10436

An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins...

6.5CVSS

6.2AI Score

0.001EPSS

2019-10-16 02:15 PM
41
cve
cve

CVE-2019-1010241

Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly line #30 (passwordVariable). The attack vector is: Attacker creates and executes.....

6.5CVSS

6.4AI Score

0.001EPSS

2019-07-19 05:15 PM
140
1
cve
cve

CVE-2019-10320

Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path, and obtain the certificate content of files containing a PKCS#12...

4.3CVSS

4.6AI Score

0.003EPSS

2019-05-21 01:29 PM
46
cve
cve

CVE-2019-10303

Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file...

8.8CVSS

8.5AI Score

0.001EPSS

2019-04-18 05:29 PM
21
cve
cve

CVE-2018-1000057

Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to configured...

4.3CVSS

4.6AI Score

0.001EPSS

2018-02-09 11:29 PM
29
cve
cve

CVE-2016-9355

An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7. An unauthorized user with physical access to an Alaris 8015 PC unit may be able to obtain unencrypted wireless network authentication credentials and.....

5.3CVSS

5.4AI Score

0.001EPSS

2017-02-13 10:59 PM
20