Jenkins Orka By Macstadium vulnerabilities

4 known vulnerabilities affecting jenkins/orka_by_macstadium.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2023-37949HIGHCVSS 7.1fixed in 1.342023-07-12
CVE-2023-37949 [HIGH] CWE-862 CVE-2023-37949: A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers wi A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
nvd
CVE-2023-24432HIGHCVSS 8.8fixed in 1.322023-01-26
CVE-2023-24432 [HIGH] CWE-352 CVE-2023-24432: A cross-site request forgery (CSRF) vulnerability in Jenkins Orka by MacStadium Plugin 1.31 and earl A cross-site request forgery (CSRF) vulnerability in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
nvd
CVE-2023-24433MEDIUMCVSS 6.5fixed in 1.322023-01-26
CVE-2023-24433 [MEDIUM] CWE-862 CVE-2023-24433: Missing permission checks in Jenkins Orka by MacStadium Plugin 1.31 and earlier allow attackers with Missing permission checks in Jenkins Orka by MacStadium Plugin 1.31 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
nvd
CVE-2023-24431MEDIUMCVSS 4.3fixed in 1.322023-01-26
CVE-2023-24431 [MEDIUM] CWE-862 CVE-2023-24431: A missing permission check in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers wi A missing permission check in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
nvd