Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 892

Количество 55 892

redhat логотип

CVE-2020-2231

около 6 лет назад

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2020-2230

около 6 лет назад

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.

CVSS3: 5.4
EPSS: Высокий
redhat логотип

CVE-2020-2229

около 6 лет назад

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2020-2226

около 6 лет назад

Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2020-2225

около 6 лет назад

Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2020-2224

около 6 лет назад

Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2020-2223

около 6 лет назад

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2020-2222

около 6 лет назад

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2020-2221

около 6 лет назад

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2020-22219

около 3 лет назад

Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2020-22218

около 3 лет назад

An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-22217

около 3 лет назад

Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2020-2220

около 6 лет назад

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2020-22083

больше 5 лет назад

jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing arbitrary code execution, and must not be used with un-trusted data

EPSS: Низкий
redhat логотип

CVE-2020-21913

почти 5 лет назад

International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-2190

около 6 лет назад

Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the In-process Script Approval page, resulting in a stored cross-site scripting vulnerability.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2020-21890

около 3 лет назад

Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2020-2182

больше 6 лет назад

Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2020-2181

больше 6 лет назад

Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2020-21710

около 3 лет назад

A divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Software GhostScript 9.50 allows remote attackers to cause a denial of service via opening of crafted PDF file.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-2231

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.

CVSS3: 5.4
5%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-2230

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.

CVSS3: 5.4
83%
Высокий
около 6 лет назад
redhat логотип
CVE-2020-2229

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
7%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-2226

Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-2225

Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-2224

Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-2223

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-2222

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-2221

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-22219

Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder.

CVSS3: 7.8
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2020-22218

An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2020-22217

Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.

CVSS3: 5.9
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2020-2220

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-22083

jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing arbitrary code execution, and must not be used with un-trusted data

6%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-21913

International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in the file tools/pkgdata/pkgdata.cpp.

CVSS3: 5.5
1%
Низкий
почти 5 лет назад
redhat логотип
CVE-2020-2190

Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the In-process Script Approval page, resulting in a stored cross-site scripting vulnerability.

CVSS3: 5.4
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2020-21890

Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2020-2182

Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances.

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2181

Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21710

A divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Software GhostScript 9.50 allows remote attackers to cause a denial of service via opening of crafted PDF file.

CVSS3: 6.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу