Skip to main content

Vendor/product archive

jenkins / icescrum CVEs

Beta · best-effort

4 CVEs tagged to jenkins / icescrum0 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-28160

Published Mar 6, 2024

Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by att…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10443

Published Oct 16, 2019

Jenkins iceScrum Plugin 1.1.4 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10442

Published Oct 16, 2019

A missing permission check in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-speci…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10441

Published Oct 16, 2019

A cross-site request forgery vulnerability in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credenti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1