Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins code dx vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-2195
A cross-site request forgery (CSRF) vulnerability in Jenkins Code Dx Plugin 3.1.0 and previous versions allows malicious users to connect to an attacker-specified URL.
Jenkins Code Dx
NA
CVE-2023-2196
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and previous versions allows attackers with Item/Read permission to check for the existence of an attacker-specified file path on an agent file system.
Jenkins Code Dx
NA
CVE-2023-2631
A missing permission check in Jenkins Code Dx Plugin 3.1.0 and previous versions allows attackers with Overall/Read permission to connect to an attacker-specified URL.
Jenkins Code Dx
NA
CVE-2023-2632
Jenkins Code Dx Plugin 3.1.0 and previous versions stores Code Dx server API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
Jenkins Code Dx
NA
CVE-2023-2633
Jenkins Code Dx Plugin 3.1.0 and previous versions does not mask Code Dx server API keys displayed on the configuration form, increasing the potential for malicious users to observe and capture them.
Jenkins Code Dx
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started