Jenkins Database vulnerabilities
3 known vulnerabilities affecting jenkins/database.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-2241HIGHCVSS 8.8≤ 1.62020-09-01
CVE-2020-2241 [HIGH] CWE-352 CVE-2020-2241: A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows
A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect to an attacker-specified database server using attacker-specified credentials.
nvd
CVE-2020-2240HIGHCVSS 8.8≤ 1.62020-09-01
CVE-2020-2240 [HIGH] CWE-352 CVE-2020-2240: A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows
A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to execute arbitrary SQL scripts.
nvd
CVE-2020-2242MEDIUMCVSS 6.5≤ 1.62020-09-01
CVE-2020-2242 [MEDIUM] CWE-862 CVE-2020-2242: A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/
A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified database server using attacker-specified credentials.
nvd