CVE-2018-1999001
- EPSS 27.31%
- Veröffentlicht 23.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:01
A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from the Jenkin...
CVE-2018-1999002
- EPSS 92.22%
- Veröffentlicht 23.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:01
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the...
CVE-2018-1999003
- EPSS 0.11%
- Veröffentlicht 23.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:01
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.
CVE-2018-1999004
- EPSS 0.15%
- Veröffentlicht 23.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:01
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches.
CVE-2018-1999005
- EPSS 0.1%
- Veröffentlicht 23.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:01
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be execut...
CVE-2018-1999006
- EPSS 0.11%
- Veröffentlicht 23.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:01
A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date ...
CVE-2018-1999007
- EPSS 0.1%
- Veröffentlicht 23.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:01
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to d...
CVE-2018-1000192
- EPSS 0.48%
- Veröffentlicht 05.06.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:53
A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.
CVE-2018-1000193
- EPSS 0.76%
- Veröffentlicht 05.06.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:54
A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear ...
CVE-2018-1000194
- EPSS 0.47%
- Veröffentlicht 05.06.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:54
A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master secu...