Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins team foundation server vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2021-21636
A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and previous versions allows attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.
Jenkins Team Foundation Server
6.5
CVSSv3
CVE-2021-21637
A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and previous versions allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials ...
Jenkins Team Foundation Server
8.8
CVSSv3
CVE-2021-21638
A cross-site request forgery (CSRF) vulnerability in Jenkins Team Foundation Server Plugin 5.157.1 and previous versions allows malicious users to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials ...
Jenkins Team Foundation Server
3.3
CVSSv3
CVE-2020-2249
Jenkins Team Foundation Server Plugin 5.157.1 and previous versions stores a webhook secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
Jenkins Team Foundation Server
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
bypass
open redirect
CVE-2024-4358
CVE-2024-24199
CVE-2024-5550
CVE-2024-5305
CVE-2024-30373
CVE-2024-1800
deserialization
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started