CVE-2020-2101
- EPSS 1.65%
- Veröffentlicht 29.01.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:24:37
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.
CVE-2020-2102
- EPSS 1.52%
- Veröffentlicht 29.01.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:24:37
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
CVE-2020-2103
- EPSS 45.22%
- Veröffentlicht 29.01.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:24:38
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
CVE-2020-2104
- EPSS 0.47%
- Veröffentlicht 29.01.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:24:38
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.
CVE-2020-2105
- EPSS 0.68%
- Veröffentlicht 29.01.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:24:38
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
CVE-2012-4441
- EPSS 1.5%
- Veröffentlicht 18.11.2019 22:15:11
- Zuletzt bearbeitet 21.11.2024 01:42:54
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.
CVE-2012-4440
- EPSS 1.5%
- Veröffentlicht 18.11.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 01:42:54
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.
CVE-2012-4438
- EPSS 1.12%
- Veröffentlicht 18.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 01:42:53
Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.
CVE-2012-4439
- EPSS 0.44%
- Veröffentlicht 18.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 01:42:53
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.
CVE-2019-10401
- EPSS 0.54%
- Veröffentlicht 25.09.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:19:03
In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as HTML when expanded, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents (typically ...