Jenkins Project Jenkins Cons3Rt Plugin vulnerabilities
4 known vulnerabilities affecting jenkins_project/jenkins_cons3rt_plugin.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2022-41253HIGHCVSS 8.8≥ unspecified, ≤ 1.0.02022-09-21
CVE-2022-41253 [HIGH] CWE-352 CVE-2022-41253: A cross-site request forgery (CSRF) vulnerability in Jenkins CONS3RT Plugin 1.0.0 and earlier allows
A cross-site request forgery (CSRF) vulnerability in Jenkins CONS3RT Plugin 1.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
cvelistv5nvd
CVE-2022-41252MEDIUMCVSS 4.3≥ unspecified, ≤ 1.0.02022-09-21
CVE-2022-41252 [MEDIUM] CWE-862 CVE-2022-41252: Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read
Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.
cvelistv5nvd
CVE-2022-41254MEDIUMCVSS 6.5≥ unspecified, ≤ 1.0.02022-09-21
CVE-2022-41254 [MEDIUM] CWE-862 CVE-2022-41254: Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/R
Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
cvelistv5nvd
CVE-2022-41255MEDIUMCVSS 6.5≥ unspecified, ≤ 1.0.02022-09-21
CVE-2022-41255 [MEDIUM] CWE-522 CVE-2022-41255: Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml file
Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
cvelistv5nvd