Jenkins Openshift Deployer vulnerabilities

7 known vulnerabilities affecting jenkins/openshift_deployer.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2022-36906MEDIUMCVSS 6.5≤ 1.2.02022-07-27
CVE-2022-36906 [MEDIUM] CWE-352 CVE-2022-36906: A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and ear A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password.
nvd
CVE-2022-36908MEDIUMCVSS 6.5≤ 1.2.02022-07-27
CVE-2022-36908 [MEDIUM] CWE-352 CVE-2022-36908: A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and ear A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller file system to an attacker-specified URL.
nvd
CVE-2022-36909MEDIUMCVSS 6.5≤ 1.2.02022-07-27
CVE-2022-36909 [MEDIUM] CWE-862 CVE-2022-36909: A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers w A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller file system to an attacker-specified URL.
nvd
CVE-2022-36907MEDIUMCVSS 6.5≤ 1.2.02022-07-27
CVE-2022-36907 [MEDIUM] CWE-862 CVE-2022-36907: A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers w A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.
nvd
CVE-2020-2155MEDIUMCVSS 5.3≤ 1.2.02020-03-09
CVE-2020-2155 [MEDIUM] CWE-319 CVE-2020-2155: Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text a Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
nvd
CVE-2019-1003081MEDIUMCVSS 6.5≤ 1.2.02019-04-04
CVE-2019-1003081 [MEDIUM] CWE-862 CVE-2019-1003081: A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployAppli A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
nvd
CVE-2019-1003080MEDIUMCVSS 6.5≤ 1.2.02019-04-04
CVE-2019-1003080 [MEDIUM] CWE-352 CVE-2019-1003080: A cross-site request forgery vulnerability in Jenkins OpenShift Deployer Plugin in the DeployApplica A cross-site request forgery vulnerability in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers to initiate a connection to an attacker-specified server.
nvd