Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins mercurial vulnerabilities and exploits
(subscribe to this query)
4
CVSSv2
CVE-2020-2305
Jenkins Mercurial Plugin 2.11 and previous versions does not configure its XML parser to prevent XML external entity (XXE) attacks.
Jenkins Mercurial
5
CVSSv2
CVE-2018-1000112
An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and previous versions in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.
Jenkins Mercurial
4
CVSSv2
CVE-2020-2306
A missing permission check in Jenkins Mercurial Plugin 2.11 and previous versions allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
Jenkins Mercurial
NA
CVE-2022-43410
Jenkins Mercurial Plugin 1251.va_b_121f184902 and previous versions provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.
Jenkins Mercurial
5
CVSSv2
CVE-2022-30948
Jenkins Mercurial Plugin 2.16 and previous versions allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM cont...
Jenkins Mercurial
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3581
reflected XSS
CVE-2024-26925
CVE-2024-27956
LFI
CVE-2024-3607
CVE-2024-3107
CVE-2024-3295
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started