×
Directly using Runtime#exec and similar Java APIs is usually a bug and can in some cases constitute a security vulnerability: While users with the permissions ...
This throws an exception if the user accessing this URL doesn't have Administer permission. If the administrator configured no security mechanism, the ...
It is defined by the Jenkins URL specified in the global configuration. --httpsListenAddress=$HTTPS_HOST. Binds Jenkins to listen for HTTPS requests on the IP ...
Jul 12, 2023 · This allows attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site after ...
Missing: misc/ | Show results with:misc/
Oct 25, 2023 · This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. GitHub Plugin 1.37.
Mar 8, 2023 · This advisory announces vulnerabilities in the following Jenkins deliverables: Jenkins (core); update-center2. Descriptions. XSS vulnerability ...
Missing: misc/ | Show results with:misc/
Sep 6, 2023 · This advisory announces vulnerabilities in the following Jenkins deliverables: Assembla Auth Plugin · AWS CodeCommit Trigger Plugin ...
Missing: misc/ | Show results with:misc/
Jan 24, 2023 · This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.
Missing: misc/ | Show results with:misc/
Feb 15, 2022 · This allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.
Missing: misc/ | Show results with:misc/
May 16, 2023 · This advisory announces vulnerabilities in the following Jenkins deliverables: Ansible Plugin · AppSpider Plugin · Azure VM Agents Plugin ...
Missing: misc/ | Show results with:misc/