Jenkins Liquibase Runner vulnerabilities

4 known vulnerabilities affecting jenkins/liquibase_runner.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2020-2284HIGHCVSS 7.1≤ 1.4.52020-09-23
CVE-2020-2284 [HIGH] CWE-611 CVE-2020-2284: Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML e Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
nvd
CVE-2020-2283MEDIUMCVSS 5.4≤ 1.4.52020-09-23
CVE-2020-2283 [MEDIUM] CWE-79 CVE-2020-2283: Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control changeset files evaluated by the plugin.
nvd
CVE-2020-2285MEDIUMCVSS 4.3≤ 1.4.72020-09-23
CVE-2020-2285 [MEDIUM] CWE-862 CVE-2020-2285: A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers wit A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
nvd
CVE-2018-1000146HIGHCVSS 8.8≤ 1.3.02018-04-05
CVE-2018-1000146 [HIGH] CVE-2018-1000146: An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.
nvd