Jenkins
Jenkins Configuration AS Code: vulnerabilidades y CVE
Jenkins Configuration AS Code tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-23106 | Media (5.3) | 1.1% | — | 12 ene 2022 | Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication… |
| CVE-2019-10367 | Media (5.5) | 0.38% | — | 7 ago 2019 | Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging the configuration being applied. |
| CVE-2019-10363 | Media (4.9) | 0.61% | — | 31 jul 2019 | Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form. |
| CVE-2019-10362 | Media (5.4) | 0.74% | — | 31 jul 2019 | Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with permission to change Jenkins system… |
| CVE-2019-10345 | Media (5.5) | 0.33% | — | 31 jul 2019 | Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export. |
| CVE-2019-10344 | Media (4.3) | 0.69% | — | 31 jul 2019 | Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema and documentation for this plugin… |
| CVE-2019-10343 | Baja (3.3) | 0.37% | — | 31 jul 2019 | Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden when logging the configuration being applied. |
| CVE-2018-1000610 | Alta (8.8) | 0.90% | — | 26 jun 2018 | A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java… |
| CVE-2018-1000609 | Media (6.5) | 0.99% | — | 26 jun 2018 | A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overall/Read access to obtain the YAML export… |