Aggregator
CVE-2023-30527 | WSO2 Oauth Plugin up to 1.0 on Jenkins Controller File System config.xml information disclosure
1 year 5 months ago
A vulnerability was found in WSO2 Oauth Plugin up to 1.0 on Jenkins. It has been rated as problematic. This issue affects some unknown processing of the file config.xml of the component Controller File System Handler. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2023-30527. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2023-30521 | Assembla Merge Request Builder Plugin up to 1.1.13 on Jenkins permission
1 year 5 months ago
A vulnerability classified as critical has been found in Assembla Merge Request Builder Plugin up to 1.1.13 on Jenkins. Affected is an unknown function. The manipulation leads to permission issues.
This vulnerability is traded as CVE-2023-30521. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-30523 | Report Portal Plugin up to 0.5 on Jenkins Controller File System permission
1 year 5 months ago
A vulnerability classified as critical was found in Report Portal Plugin up to 0.5 on Jenkins. Affected by this vulnerability is an unknown functionality of the component Controller File System Handler. The manipulation leads to permission issues.
This vulnerability is known as CVE-2023-30523. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2023-30524 | Report Portal Plugin up to 0.5 on Jenkins Configuration Form information disclosure
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in Report Portal Plugin up to 0.5 on Jenkins. Affected by this issue is some unknown functionality of the component Configuration Form Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2023-30524. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2023-30526 | Report Portal Plugin up to 0.5 on Jenkins permission
1 year 5 months ago
A vulnerability, which was classified as critical, was found in Report Portal Plugin up to 0.5 on Jenkins. This affects an unknown part. The manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2023-30526. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2023-30530 | Consul KV Builder Plugin up to 2.0.13 on Jenkins Controller File System cleartext storage
1 year 5 months ago
A vulnerability has been found in Consul KV Builder Plugin up to 2.0.13 on Jenkins and classified as problematic. This vulnerability affects unknown code of the component Controller File System Handler. The manipulation leads to cleartext storage of sensitive information.
This vulnerability was named CVE-2023-30530. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2023-30531 | Consul KV Builder Plugin up to 2.0.13 on Jenkins Configuration Form information disclosure
1 year 5 months ago
A vulnerability was found in Consul KV Builder Plugin up to 2.0.13 on Jenkins and classified as problematic. This issue affects some unknown processing of the component Configuration Form Handler. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2023-30531. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-30532 | TurboScript Plugin up to 1.3 on Jenkins permission
1 year 5 months ago
A vulnerability was found in TurboScript Plugin up to 1.3 on Jenkins. It has been classified as critical. Affected is an unknown function. The manipulation leads to permission issues.
This vulnerability is traded as CVE-2023-30532. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2023-30520 | Quay.io Trigger Plugin up to 0.1 on Jenkins URL Scheme cross site scripting
1 year 5 months ago
A vulnerability was found in Quay.io Trigger Plugin up to 0.1 on Jenkins. It has been rated as problematic. Affected by this issue is some unknown functionality of the component URL Scheme Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2023-30520. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2023-30522 | Fogbugz Plugin up to 2.2.17 on Jenkins Request Parameter jobname permission
1 year 5 months ago
A vulnerability classified as critical has been found in Fogbugz Plugin up to 2.2.17 on Jenkins. This affects an unknown part of the component Request Parameter Handler. The manipulation of the argument jobname leads to permission issues.
This vulnerability is uniquely identified as CVE-2023-30522. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2023-30525 | Report Portal Plugin up to 0.5 on Jenkins cross-site request forgery
1 year 5 months ago
A vulnerability classified as problematic was found in Report Portal Plugin up to 0.5 on Jenkins. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2023-30525. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-30529 | Lucene-Search Plugin up to 387.v938a_ecb_f7fe9 on Jenkins HTTP Endpoint cross-site request forgery
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in Lucene-Search Plugin up to 387.v938a_ecb_f7fe9 on Jenkins. This issue affects some unknown processing of the component HTTP Endpoint. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2023-30529. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2023-30528 | WSO2 Oauth Plugin up to 1.0 on Jenkins Configuration Form information disclosure
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in WSO2 Oauth Plugin up to 1.0 on Jenkins. Affected is an unknown function of the component Configuration Form Handler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2023-30528. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-26120 | Xuxueli xxl-job /xxl-job-admin/user/add cross site scripting (SNYK-JAVA-COMXUXUELI-3248764)
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in Xuxueli xxl-job. This issue affects some unknown processing of the file /xxl-job-admin/user/add. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2023-26120. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2022-39048 | ServiceNow Tokyo cross site scripting (KB1221892)
1 year 5 months ago
A vulnerability was found in ServiceNow Tokyo and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2022-39048. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2023-30512 | CubeFS up to 3.2.1 DaemonSet information disclosure (Issue 1882)
1 year 5 months ago
A vulnerability classified as problematic has been found in CubeFS up to 3.2.1. Affected is an unknown function of the component DaemonSet. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2023-30512. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2023-30513 | Kubernetes Plugin up to 3909.v1f2c633e8590 on Jenkins Credentials log file
1 year 5 months ago
A vulnerability classified as problematic was found in Kubernetes Plugin up to 3909.v1f2c633e8590 on Jenkins. This vulnerability affects unknown code of the component Credentials Handler. The manipulation leads to sensitive information in log files.
This vulnerability was named CVE-2023-30513. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2023-30514 | Azure Key Vault Plugin up to 187.va_cd5fecd198a_ on Jenkins Credentials log file
1 year 5 months ago
A vulnerability, which was classified as problematic, has been found in Azure Key Vault Plugin up to 187.va_cd5fecd198a_ on Jenkins. This issue affects some unknown processing of the component Credentials Handler. The manipulation leads to sensitive information in log files.
The identification of this vulnerability is CVE-2023-30514. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2023-30515 | Thycotic DevOps Secrets Vault Plugin up to 1.0.0 on Jenkins Credentials log file
1 year 5 months ago
A vulnerability, which was classified as problematic, was found in Thycotic DevOps Secrets Vault Plugin up to 1.0.0 on Jenkins. Affected is an unknown function of the component Credentials Handler. The manipulation leads to sensitive information in log files.
This vulnerability is traded as CVE-2023-30515. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com