Assembla Auth
Jenkins · 2 CVEs
CVE-2023-41945
HIGH
Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in…
Sep 6, 2023
CVE-2019-10280
HIGH
Jenkins Assembla Auth Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins…
Apr 4, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-41945 | Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be grante… | HIGH | 0.66% | Sep 6, 2023 |
| CVE-2019-10280 | Jenkins Assembla Auth Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users… | HIGH | 1.74% | Apr 4, 2019 |
Showing 1 to 2 of 2 CVEs