CVE-2022-43413
- EPSS 0.59%
- Veröffentlicht 19.10.2022 16:15:10
- Zuletzt bearbeitet 08.05.2025 20:15:27
Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVE-2019-1003015
- EPSS 0.11%
- Veröffentlicht 06.02.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:17:44
An XML external entity processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/client/RestApiClient.java that allows attackers with the ability to control the HTTP server (Jenkins...
CVE-2019-1003016
- EPSS 0.16%
- Veröffentlicht 06.02.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:17:44
An exposure of sensitive information vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport/JobImportAction.java, src/main/java/org/jenkins/ci/plugins/jobimport/JobImportGlobalConfig.java, ...
CVE-2019-1003017
- EPSS 0.08%
- Veröffentlicht 06.02.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:17:44
A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allows attackers to copy jobs from a preconfigured other Jenkins instance, potentially installing additional plugins necessary to load ...