Jenkins Project Jenkins Team Concert Plugin vulnerabilities
4 known vulnerabilities affecting jenkins_project/jenkins_team_concert_plugin.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2023-3315MEDIUMCVSS 4.3≤ 2.4.12023-06-19
CVE-2023-3315 [MEDIUM] CWE-862 CVE-2023-3315: Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Over
Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
cvelistv5nvd
CVE-2019-16565HIGHCVSS 8.8≥ unspecified, ≤ 1.3.02019-12-17
CVE-2019-16565 [HIGH] CWE-352 CVE-2019-16565: A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows a
A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
cvelistv5nvd
CVE-2019-16567MEDIUMCVSS 4.3≥ unspecified, ≤ 1.3.02019-12-17
CVE-2019-16567 [MEDIUM] CWE-862 CVE-2019-16567: A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier in form-related methods
A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
cvelistv5nvd
CVE-2019-16566MEDIUMCVSS 6.5≥ unspecified, ≤ 1.3.02019-12-17
CVE-2019-16566 [MEDIUM] CWE-862 CVE-2019-16566: A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers with Ov
A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
cvelistv5nvd