Jenkins Project Jenkins Elasticbox Jenkins Kubernetes Ci Cd Plugin vulnerabilities
4 known vulnerabilities affecting jenkins_project/jenkins_elasticbox_jenkins_kubernetes_ci_cd_plugin.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2020-2211HIGHCVSS 8.8≥ unspecified, ≤ 1.32020-07-02
CVE-2020-2211 [HIGH] CWE-502 CVE-2020-2211: Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parse
Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
cvelistv5nvd
CVE-2019-10468HIGHCVSS 8.8v1.3 and earlier2019-10-23
CVE-2019-10468 [HIGH] CWE-352 CVE-2019-10468: A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin all
A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
cvelistv5nvd
CVE-2019-10470MEDIUMCVSS 6.5v1.3 and earlier2019-10-23
CVE-2019-10470 [MEDIUM] CWE-276 CVE-2019-10470: A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related met
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
cvelistv5nvd
CVE-2019-10469MEDIUMCVSS 6.5v1.3 and earlier2019-10-23
CVE-2019-10469 [MEDIUM] CWE-276 CVE-2019-10469: A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers wi
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
cvelistv5nvd