Lucene search

K

Jenkins Credentials Plugin Security Vulnerabilities

cve
cve

CVE-2024-39459

In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global credentials) or with...

6.8AI Score

0.0004EPSS

2024-06-26 05:15 PM
20
cve
cve

CVE-2023-50768

A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in...

8.8CVSS

8.6AI Score

0.001EPSS

2023-12-13 06:15 PM
18
cve
cve

CVE-2023-50769

Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in...

4.3CVSS

4.4AI Score

0.0004EPSS

2023-12-13 06:15 PM
17
cve
cve

CVE-2023-49652

Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate system-scoped credentials IDs of credentials stored in Jenkins...

2.7CVSS

3.4AI Score

0.0004EPSS

2023-11-29 02:15 PM
16
cve
cve

CVE-2023-49653

Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled...

6.5CVSS

6.3AI Score

0.0005EPSS

2023-11-29 02:15 PM
25
cve
cve

CVE-2023-46652

A missing permission check in Jenkins lambdatest-automation Plugin 1.20.9 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of LAMBDATEST credentials stored in...

4.3CVSS

4.4AI Score

0.0004EPSS

2023-10-25 06:17 PM
17
cve
cve

CVE-2023-46653

Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, potentially resulting in its...

6.5CVSS

6.4AI Score

0.0005EPSS

2023-10-25 06:17 PM
22
cve
cve

CVE-2023-46651

Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. This fix has been backported to...

6.5CVSS

6.3AI Score

0.0005EPSS

2023-10-25 06:17 PM
21
cve
cve

CVE-2023-4777

An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins and to connect to an.....

4.3CVSS

4.5AI Score

0.0004EPSS

2023-09-08 09:15 AM
25
cve
cve

CVE-2023-41946

A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to connect to Frugal Testing using attacker-specified credentials, and to retrieve test IDs and names from Frugal Testing, if a valid credential corresponds to the attacker-specified....

3.5CVSS

4AI Score

0.0004EPSS

2023-09-06 01:15 PM
82
cve
cve

CVE-2023-41941

A missing permission check in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in...

4.3CVSS

4.4AI Score

0.0004EPSS

2023-09-06 01:15 PM
79
cve
cve

CVE-2023-41947

A missing permission check in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to Frugal Testing using attacker-specified...

4.3CVSS

4.4AI Score

0.0004EPSS

2023-09-06 01:15 PM
81
cve
cve

CVE-2023-41934

Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if "Treat username as secret" is...

5.3CVSS

5.2AI Score

0.0005EPSS

2023-09-06 01:15 PM
76
cve
cve

CVE-2023-41937

Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by...

7.5CVSS

7.4AI Score

0.001EPSS

2023-09-06 01:15 PM
190
cve
cve

CVE-2023-4302

A missing permission check in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in...

4.3CVSS

4.4AI Score

0.0004EPSS

2023-08-21 11:15 PM
224
cve
cve

CVE-2023-4301

A cross-site request forgery (CSRF) vulnerability in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in...

5.4CVSS

5.4AI Score

0.0005EPSS

2023-08-21 11:15 PM
231
cve
cve

CVE-2023-40347

Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled...

6.5CVSS

6.3AI Score

0.0005EPSS

2023-08-16 03:15 PM
223
cve
cve

CVE-2023-40341

A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and earlier allows attackers to connect to an attacker-specified URL, capturing GitHub credentials associated with an attacker-specified...

8.8CVSS

8.6AI Score

0.001EPSS

2023-08-16 03:15 PM
238
cve
cve

CVE-2023-40339

Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they're written to the build...

7.5CVSS

7.3AI Score

0.001EPSS

2023-08-16 03:15 PM
225
cve
cve

CVE-2023-40340

Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in the Npm config file in Pipeline build...

7.5CVSS

7.5AI Score

0.001EPSS

2023-08-16 03:15 PM
220
cve
cve

CVE-2023-40345

Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission to access and capture credentials they are not entitled...

6.5CVSS

6.3AI Score

0.001EPSS

2023-08-16 03:15 PM
220
cve
cve

CVE-2023-40344

A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in...

4.3CVSS

4.3AI Score

0.001EPSS

2023-08-16 03:15 PM
216
cve
cve

CVE-2023-39154

Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with global Item/Configure permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in....

6.5CVSS

6.3AI Score

0.001EPSS

2023-07-26 02:15 PM
205
cve
cve

CVE-2023-39152

Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i.e., replaced with asterisks) in the build log in some...

6.5CVSS

6.4AI Score

0.001EPSS

2023-07-26 02:15 PM
198
cve
cve

CVE-2023-37965

A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in...

7.1CVSS

6.7AI Score

0.001EPSS

2023-07-12 04:15 PM
18
cve
cve

CVE-2023-37964

A cross-site request forgery (CSRF) vulnerability in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in...

8.8CVSS

8.6AI Score

0.001EPSS

2023-07-12 04:15 PM
21
cve
cve

CVE-2023-37955

A cross-site request forgery (CSRF) vulnerability in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified...

6.5CVSS

6.4AI Score

0.0005EPSS

2023-07-12 04:15 PM
15
cve
cve

CVE-2023-37943

Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active....

5.9CVSS

5.5AI Score

0.001EPSS

2023-07-12 04:15 PM
20
cve
cve

CVE-2023-37951

Jenkins mabl Plugin 0.0.46 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled...

6.5CVSS

6.4AI Score

0.001EPSS

2023-07-12 04:15 PM
11
cve
cve

CVE-2023-37950

A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in...

4.3CVSS

4.4AI Score

0.0005EPSS

2023-07-12 04:15 PM
14
cve
cve

CVE-2023-37944

A missing permission check in Jenkins Datadog Plugin 5.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in...

6.5CVSS

6.2AI Score

0.001EPSS

2023-07-12 04:15 PM
18
cve
cve

CVE-2023-37956

A missing permission check in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified...

6.5CVSS

6.3AI Score

0.0005EPSS

2023-07-12 04:15 PM
18
cve
cve

CVE-2023-37952

A cross-site request forgery (CSRF) vulnerability in Jenkins mabl Plugin 0.0.46 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in...

6.5CVSS

6.4AI Score

0.0005EPSS

2023-07-12 04:15 PM
18
cve
cve

CVE-2023-37953

A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in...

6.5CVSS

6.3AI Score

0.001EPSS

2023-07-12 04:15 PM
13
cve
cve

CVE-2023-37949

A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in...

7.1CVSS

6.7AI Score

0.001EPSS

2023-07-12 04:15 PM
12
cve
cve

CVE-2023-35148

A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect to an attacker-specified URL, capturing credentials stored in...

6.5CVSS

6.3AI Score

0.001EPSS

2023-06-14 01:15 PM
29
cve
cve

CVE-2023-35149

A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in...

6.5CVSS

6.2AI Score

0.001EPSS

2023-06-14 01:15 PM
35
cve
cve

CVE-2023-32998

A cross-site request forgery (CSRF) vulnerability in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers to connect to an attacker-specified URL and send an HTTP POST request with a JSON payload consisting of attacker-specified...

8.8CVSS

8.6AI Score

0.001EPSS

2023-05-16 05:15 PM
19
cve
cve

CVE-2023-32999

A missing permission check in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL and send an HTTP POST request with a JSON payload consisting of attacker-specified...

4.3CVSS

4.4AI Score

0.0005EPSS

2023-05-16 05:15 PM
20
cve
cve

CVE-2023-33000

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture...

7.5CVSS

7.5AI Score

0.001EPSS

2023-05-16 05:15 PM
19
cve
cve

CVE-2023-33001

Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is...

7.5CVSS

7.5AI Score

0.001EPSS

2023-05-16 05:15 PM
29
cve
cve

CVE-2023-32990

A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another...

6.5CVSS

6.2AI Score

0.0005EPSS

2023-05-16 05:15 PM
26
cve
cve

CVE-2023-32988

A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in...

4.3CVSS

4.3AI Score

0.0005EPSS

2023-05-16 04:15 PM
26
cve
cve

CVE-2023-32989

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another...

8.8CVSS

8.6AI Score

0.001EPSS

2023-05-16 04:15 PM
25
cve
cve

CVE-2023-32987

A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier allows attackers to connect to an attacker-specified LDAP server using attacker-specified...

8.8CVSS

8.6AI Score

0.001EPSS

2023-05-16 04:15 PM
15
cve
cve

CVE-2023-32978

A cross-site request forgery (CSRF) vulnerability in Jenkins LDAP Plugin allows attackers to connect to an attacker-specified LDAP server using attacker-specified...

4.3CVSS

4.5AI Score

0.0005EPSS

2023-05-16 04:15 PM
18
cve
cve

CVE-2023-30518

A missing permission check in Jenkins Thycotic Secret Server Plugin 1.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in...

4.3CVSS

4.4AI Score

0.001EPSS

2023-04-12 06:15 PM
15
cve
cve

CVE-2023-30515

Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is...

7.5CVSS

7.4AI Score

0.002EPSS

2023-04-12 06:15 PM
19
cve
cve

CVE-2023-30514

Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is...

7.5CVSS

7.4AI Score

0.002EPSS

2023-04-12 06:15 PM
20
cve
cve

CVE-2023-30513

Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is...

7.5CVSS

7.3AI Score

0.002EPSS

2023-04-12 06:15 PM
26
Total number of security vulnerabilities366