Jenkins Project Jenkins Mattermost Notification Plugin vulnerabilities
2 known vulnerabilities affecting jenkins_project/jenkins_mattermost_notification_plugin.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2019-10459MEDIUMCVSS 6.5v2.7.0 and earlier2019-10-23
CVE-2019-10459 [MEDIUM] CWE-522 CVE-2019-10459: Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret tok
Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in its global configuration file and job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
nvd
CVE-2019-1003026MEDIUMCVSS 4.3v2.6.2 and earlier2019-02-20
CVE-2019-1003026 [MEDIUM] CWE-918 CVE-2019-1003026: A server-side request forgery vulnerability exists in Jenkins Mattermost Notification Plugin 2.6.2 a
A server-side request forgery vulnerability exists in Jenkins Mattermost Notification Plugin 2.6.2 and earlier in MattermostNotifier.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified Mattermost server and room and send a message.
nvd