Jenkins / Config File Provider
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-40339 | jenkins-plugins: config-file-provider: Improper masking of credentials in Config File Provider Plugin | HIGH | 7.5 | Aug 16, 2023 |
| CVE-2021-21645 | jenkins-2-plugins/config-file-provider: Does not perform permission checks in several HTTP endpoints. | MEDIUM | 4.3 | Apr 21, 2021 |
| CVE-2021-21644 | jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability. | MEDIUM | 6.3 | Apr 21, 2021 |
| CVE-2021-21643 | jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. | MEDIUM | 6.5 | Apr 21, 2021 |
| CVE-2021-21642 | jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. | HIGH | 8.1 | Apr 21, 2021 |
| CVE-2019-1003014 | jenkins-plugin-config-file-provider: Stored XSS vulnerability in Config File Provider Plugin (SECURITY-1253) | MEDIUM | 4.8 | Feb 6, 2019 |
| CVE-2018-1000414 | A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigFileAction.… | HIGH | 8.1 | Jan 9, 2019 |
| CVE-2018-1000413 | A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users w… | MEDIUM | 5.4 | Jan 9, 2019 |
| CVE-2017-1000104 | The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read acc… | MEDIUM | 6.5 | Oct 4, 2017 |
Showing 1 to 9 of 9 CVEs