Jenkins Project Jenkins Orka By Macstadium Plugin vulnerabilities
4 known vulnerabilities affecting jenkins_project/jenkins_orka_by_macstadium_plugin.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-37949HIGHCVSS 7.1≤ 1.332023-07-12
CVE-2023-37949 [HIGH] CWE-862 CVE-2023-37949: A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers wi
A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
cvelistv5nvd
CVE-2023-24432HIGHCVSS 8.8≥ unspecified, ≤ 1.312023-01-26
CVE-2023-24432 [HIGH] CWE-352 CVE-2023-24432: A cross-site request forgery (CSRF) vulnerability in Jenkins Orka by MacStadium Plugin 1.31 and earl
A cross-site request forgery (CSRF) vulnerability in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
cvelistv5nvd
CVE-2023-24433MEDIUMCVSS 6.5≥ unspecified, ≤ 1.312023-01-26
CVE-2023-24433 [MEDIUM] CWE-862 CVE-2023-24433: Missing permission checks in Jenkins Orka by MacStadium Plugin 1.31 and earlier allow attackers with
Missing permission checks in Jenkins Orka by MacStadium Plugin 1.31 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
cvelistv5nvd
CVE-2023-24431MEDIUMCVSS 4.3≥ unspecified, ≤ 1.312023-01-26
CVE-2023-24431 [MEDIUM] CWE-862 CVE-2023-24431: A missing permission check in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers wi
A missing permission check in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
cvelistv5nvd