Jenkins Project Jenkins Pipeline Github Notify Step Plugin vulnerabilities
3 known vulnerabilities affecting jenkins_project/jenkins_pipeline_github_notify_step_plugin.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2020-2116HIGHCVSS 8.8≥ unspecified, ≤ 1.0.42020-02-12
CVE-2020-2116 [HIGH] CWE-352 CVE-2020-2116: A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and e
A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
cvelistv5nvd
CVE-2020-2117MEDIUMCVSS 4.3≥ unspecified, ≤ 1.0.42020-02-12
CVE-2020-2117 [MEDIUM] CWE-276 CVE-2020-2117: A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows at
A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
cvelistv5nvd
CVE-2020-2118MEDIUMCVSS 4.3≥ unspecified, ≤ 1.0.42020-02-12
CVE-2020-2118 [MEDIUM] CWE-276 CVE-2020-2118: A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-r
A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
cvelistv5nvd