Jenkins

Docker Commons

2 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.42%
  • Published 12.01.2022 20:15:08
  • Last modified 21.11.2024 06:43:10

Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously...

  • EPSS 0.05%
  • Published 05.10.2017 01:29:03
  • Last modified 20.04.2025 01:37:25

Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use to authenticate with a Docker Registry. This functionality did not check permissions, allowing any user with Over...