CVE-2020-2251
- EPSS 0.04%
- Veröffentlicht 01.09.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:25:05
Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.
CVE-2020-2229
- EPSS 2.23%
- Veröffentlicht 12.08.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:25:01
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
CVE-2020-2230
- EPSS 0.33%
- Veröffentlicht 12.08.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:25:01
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
CVE-2020-2231
- EPSS 0.47%
- Veröffentlicht 12.08.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:25:01
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure p...
CVE-2020-2221
- EPSS 0.54%
- Veröffentlicht 15.07.2020 18:15:37
- Zuletzt bearbeitet 21.11.2024 05:24:59
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.
CVE-2020-2222
- EPSS 0.53%
- Veröffentlicht 15.07.2020 18:15:37
- Zuletzt bearbeitet 21.11.2024 05:25:00
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.
CVE-2020-2223
- EPSS 0.53%
- Veröffentlicht 15.07.2020 18:15:37
- Zuletzt bearbeitet 21.11.2024 05:25:00
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.
CVE-2020-2220
- EPSS 0.43%
- Veröffentlicht 15.07.2020 18:15:36
- Zuletzt bearbeitet 21.11.2024 05:24:59
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
CVE-2020-2161
- EPSS 0.3%
- Veröffentlicht 25.03.2020 17:15:15
- Zuletzt bearbeitet 21.11.2024 05:24:49
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to defin...
CVE-2020-2162
- EPSS 0.43%
- Veröffentlicht 25.03.2020 17:15:15
- Zuletzt bearbeitet 21.11.2024 05:24:49
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.