Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins code dx vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2023-2631
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and previous versions allows attackers with Overall/Read permission to connect to an attacker-specified URL.
Jenkins Code Dx
4.3
CVSSv3
CVE-2023-2632
Jenkins Code Dx Plugin 3.1.0 and previous versions stores Code Dx server API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
Jenkins Code Dx
4.3
CVSSv3
CVE-2023-2633
Jenkins Code Dx Plugin 3.1.0 and previous versions does not mask Code Dx server API keys displayed on the configuration form, increasing the potential for malicious users to observe and capture them.
Jenkins Code Dx
3.5
CVSSv3
CVE-2023-2195
A cross-site request forgery (CSRF) vulnerability in Jenkins Code Dx Plugin 3.1.0 and previous versions allows malicious users to connect to an attacker-specified URL.
Jenkins Code Dx
4.3
CVSSv3
CVE-2023-2196
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and previous versions allows attackers with Item/Read permission to check for the existence of an attacker-specified file path on an agent file system.
Jenkins Code Dx
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-40673
CVE-2024-36674
CVE-2024-27348
unspecified
CVE-2024-24919
CVE-2024-4870
malicious code
CVE-2024-2019
hard-coded
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started