Rapiddeploy
Jenkins · 4 CVEs
CVE-2020-2171
HIGH
Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attac…
Mar 25, 2020
CVE-2020-2170
MEDIUM
Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remot…
Mar 25, 2020
CVE-2019-16571
MEDIUM
A missing permission check in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers with Overall/Read permission…
Dec 17, 2019
CVE-2019-16570
HIGH
A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to…
Dec 17, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-2171 | Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | HIGH | 1.15% | Mar 25, 2020 |
| CVE-2020-2170 | Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote server, resulting in a stored XSS vuln… | MEDIUM | 0.73% | Mar 25, 2020 |
| CVE-2019-16571 | A missing permission check in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web… | MEDIUM | 0.71% | Dec 17, 2019 |
| CVE-2019-16570 | A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web server. | HIGH | 0.69% | Dec 17, 2019 |
Showing 1 to 4 of 4 CVEs