Jenkins Team Foundation Server vulnerabilities
4 known vulnerabilities affecting jenkins/team_foundation_server.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2LOW1
Vulnerabilities
Page 1 of 1
CVE-2021-21638HIGHCVSS 8.8≤ 5.157.12021-03-30
CVE-2021-21638 [HIGH] CWE-352 CVE-2021-21638: A cross-site request forgery (CSRF) vulnerability in Jenkins Team Foundation Server Plugin 5.157.1 a
A cross-site request forgery (CSRF) vulnerability in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
nvd
CVE-2021-21636MEDIUMCVSS 4.3≤ 5.157.12021-03-30
CVE-2021-21636 [MEDIUM] CWE-862 CVE-2021-21636: A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attac
A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.
nvd
CVE-2021-21637MEDIUMCVSS 6.5≤ 5.157.12021-03-30
CVE-2021-21637 [MEDIUM] CWE-862 CVE-2021-21637: A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attac
A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
nvd
CVE-2020-2249LOWCVSS 3.3≤ 5.157.12020-09-01
CVE-2020-2249 [LOW] CWE-311 CVE-2020-2249: Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its
Jenkins Team Foundation Server Plugin 5.157.1 and earlier stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
nvd