Jenkins

Sitemonitor

2 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 25.85%
  • Published 29.03.2022 13:15:09
  • Last modified 21.11.2024 06:56:51

Jenkins SiteMonitor Plugin 0.6 and earlier does not escape URLs of sites to monitor in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • EPSS 0.06%
  • Published 30.04.2019 13:29:05
  • Last modified 21.11.2024 04:18:52

Jenkins SiteMonitor Plugin 0.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.