Skip to main content

Vendor/product archive

jenkins / configuration_as_code CVEs

Beta · best-effort

9 CVEs tagged to jenkins / configuration_as_code0 Critical, 1 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2022-23106

Published Jan 12, 2022

Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical me…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10367

Published Aug 7, 2019

Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10363

Published Jul 31, 2019

Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10362

Published Jul 31, 2019

Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when exporting, allowing attackers with…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10344

Published Jul 31, 2019

Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10343

Published Jul 31, 2019

Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden when logging the configuration being applied.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1000610

Published Jun 26, 2018

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigura…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000609

Published Jun 26, 2018

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1