CVE-2024-23901
- EPSS 0.09%
- Published 24.01.2024 18:15:09
- Last modified 30.05.2025 15:15:39
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share a project, resulting in a crafted Pipeline being built b...
CVE-2024-23902
- EPSS 0.05%
- Published 24.01.2024 18:15:09
- Last modified 30.05.2025 15:15:39
A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier allows attackers to connect to an attacker-specified URL.
CVE-2024-23903
- EPSS 0.08%
- Published 24.01.2024 18:15:09
- Last modified 21.11.2024 08:58:40
Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obt...
CVE-2018-1000185
- EPSS 0.04%
- Published 05.06.2018 20:29:00
- Last modified 21.11.2024 03:39:52
A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
CVE-2017-1000087
- EPSS 0.02%
- Published 05.10.2017 01:29:03
- Last modified 20.04.2025 01:37:25
GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of val...
CVE-2017-1000091
- EPSS 0.07%
- Published 05.10.2017 01:29:03
- Last modified 20.04.2025 01:37:25
GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan Credentials are correct). This functionality improperly checked permissions, allowing any ...