Jenkins Kubernetes Ci vulnerabilities

4 known vulnerabilities affecting jenkins/kubernetes_ci.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2020-2211HIGHCVSS 8.8≤ 1.32020-07-02
CVE-2020-2211 [HIGH] CWE-502 CVE-2020-2211: Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parse Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
nvd
CVE-2019-10468HIGHCVSS 8.8≤ 1.32019-10-23
CVE-2019-10468 [HIGH] CWE-352 CVE-2019-10468: A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin all A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
nvd
CVE-2019-10470MEDIUMCVSS 6.5≤ 1.32019-10-23
CVE-2019-10470 [MEDIUM] CWE-276 CVE-2019-10470: A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related met A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
nvd
CVE-2019-10469MEDIUMCVSS 6.5≤ 1.32019-10-23
CVE-2019-10469 [MEDIUM] CWE-276 CVE-2019-10469: A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers wi A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
nvd