Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins build environment vulnerabilities and exploits
(subscribe to this query)
NA
CVE_2022_40684
Official Writeup - Simple CTF 2.0 Created: April 23, 2024 7:50 PM Today I completed an other room on TryHackMe with a simple file-upload vulnerability which I built. I have tried for dancing around this whole CTF machine and getting a lot of walls of challenges in the end it co...
1 Github repository
NA
CVE-2023-28677
Jenkins Convert To Pipeline Plugin 1.0 and previous versions uses basic string concatenation to convert Freestyle projects' Build Environment, Build Steps, and Post-build Actions to the equivalent Pipeline step invocations, allowing attackers able to configure Freestyle proj...
Jenkins Convert To Pipeline
356
VMScore
CVE-2019-10407
Jenkins Project Inheritance Plugin 2.0.0 and previous versions displayed a list of environment variables passed to a build without masking sensitive variables contributed by the Mask Passwords Plugin.
Jenkins Project Inheritance
312
VMScore
CVE-2019-10395
Jenkins Build Environment Plugin 1.6 and previous versions did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Jenkins 2.145, 2.138.1, or older, exploitable by users able to change various job/build properties.
Jenkins Build Environment
356
VMScore
CVE-2018-1000057
Jenkins Credentials Binding Plugin 1.14 and previous versions masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but s...
Jenkins Credentials Binding
356
VMScore
CVE-2016-3721
Jenkins prior to 2.3 and LTS prior to 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
Redhat Openshift 3.1
Redhat Openshift 3.2
Jenkins Jenkins
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
buffer overflow
type confusion
server-side request forgery
CVE-2024-38440
CVE-2024-27801
CVE-2024-5868
CVE-2024-0582
CVE-2024-37643
CVE-2024-3105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started