Jenkins Project Jenkins Ansible Tower Plugin vulnerabilities
3 known vulnerabilities affecting jenkins_project/jenkins_ansible_tower_plugin.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-10310HIGHCVSS 8.8v0.9.1 and earlier2019-04-30
CVE-2019-10310 [HIGH] CWE-352 CVE-2019-10310: A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the
A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credential
cvelistv5nvd
CVE-2019-10311HIGHCVSS 8.8v0.9.1 and earlier2019-04-30
CVE-2019-10311 [HIGH] CWE-862 CVE-2019-10311: A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallatio
A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnection form validation method allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credent
cvelistv5nvd
CVE-2019-10312MEDIUMCVSS 4.3v0.9.1 and earlier2019-04-30
CVE-2019-10312 [MEDIUM] CWE-862 CVE-2019-10312: A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallatio
A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doFillTowerCredentialsIdItems method allowed attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.
cvelistv5nvd