Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
oracle communications cloud native core automated test suite 1.9.0 vulnerabilities and exploits
(subscribe to this query)
4
CVSSv2
CVE-2022-20614
A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and previous versions allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
Jenkins Mailer 391.ve4a 38c1b Cf4b
Jenkins Mailer
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
4
CVSSv2
CVE-2018-1999004
A Improper authorization vulnerability exists in Jenkins 2.132 and previous versions, 2.121.1 and previous versions in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches.
Jenkins Jenkins
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
1 Github repository
4
CVSSv2
CVE-2018-1999003
A Improper authorization vulnerability exists in Jenkins 2.132 and previous versions, 2.121.1 and previous versions in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.
Jenkins Jenkins
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
4
CVSSv2
CVE-2018-1000192
A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.
Jenkins Jenkins
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
4
CVSSv2
CVE-2018-1000193
A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other...
Jenkins Jenkins
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
4
CVSSv2
CVE-2018-6356
Jenkins prior to 2.107 and Jenkins LTS prior to 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should n...
Jenkins Jenkins
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
3.5
CVSSv2
CVE-2022-20615
Jenkins Matrix Project Plugin 1.19 and previous versions does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
Jenkins Matrix Project
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
3.5
CVSSv2
CVE-2019-10383
A stored cross-site scripting vulnerability in Jenkins 2.191 and previous versions, LTS 2.176.2 and previous versions allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.
Jenkins Jenkins
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
Redhat Openshift Container Platform 3.11
Redhat Openshift Container Platform 4.1
3.5
CVSSv2
CVE-2019-1003050
The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and previous versions and Jenkins LTS 2.164.1 and previous versions, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job...
Jenkins Jenkins
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
Redhat Openshift Container Platform 3.11
3.5
CVSSv2
CVE-2018-1999005
A cross-site scripting vulnerability exists in Jenkins 2.132 and previous versions, 2.121.1 and previous versions in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in anot...
Jenkins Jenkins
Oracle Communications Cloud Native Core Automated Test Suite 1.9.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »