Jenkins Project Jenkins Database Plugin vulnerabilities
3 known vulnerabilities affecting jenkins_project/jenkins_database_plugin.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-2241HIGHCVSS 8.8≥ unspecified, ≤ 1.62020-09-01
CVE-2020-2241 [HIGH] CWE-352 CVE-2020-2241: A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows
A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect to an attacker-specified database server using attacker-specified credentials.
cvelistv5nvd
CVE-2020-2240HIGHCVSS 8.8≥ unspecified, ≤ 1.62020-09-01
CVE-2020-2240 [HIGH] CWE-352 CVE-2020-2240: A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows
A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to execute arbitrary SQL scripts.
cvelistv5nvd
CVE-2020-2242MEDIUMCVSS 6.5≥ unspecified, ≤ 1.62020-09-01
CVE-2020-2242 [MEDIUM] CWE-862 CVE-2020-2242: A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/
A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified database server using attacker-specified credentials.
cvelistv5nvd