Jenkins

Tics

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.23%
  • Veröffentlicht 02.09.2026 15:40:57
  • Zuletzt bearbeitet 03.09.2026 17:13:16

OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.

  • EPSS 0.95%
  • Veröffentlicht 13.01.2021 16:15:14
  • Zuletzt bearbeitet 21.11.2024 05:48:41

Jenkins TICS Plugin 2020.3.0.6 and earlier does not escape TICS service responses, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control TICS service response content.