Jenkins
Jenkins Config File Provider: vulnerabilidades y CVE
Jenkins Config File Provider tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-40339 | Alta (7.5) | 0.78% | — | 16 ago 2023 | Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they're written to the build log. |
| CVE-2021-21645 | Media (4.3) | 0.89% | — | 21 abr 2021 | Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs. |
| CVE-2021-21644 | Media (5.4) | 1.1% | — | 21 abr 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID. |
| CVE-2021-21643 | Media (6.5) | 1.1% | — | 21 abr 2021 | Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped… |
| CVE-2021-21642 | Alta (8.1) | 38% | — | 21 abr 2021 | Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2019-1003014 | Media (4.8) | 0.88% | — | 6 feb 2019 | An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared… |
| CVE-2018-1000414 | Alta (8.1) | 0.83% | — | 9 ene 2019 | A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigFileAction.java that allows creating and editing configuration file… |
| CVE-2018-1000413 | Media (5.4) | 0.95% | — | 9 ene 2019 | A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert… |
| CVE-2017-1000104 | Media (6.5) | 0.82% | — | 5 oct 2017 | The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs directly that… |