VYPR

Maven package

org.jenkins-ci.plugins/pipeline-githubnotify-step

pkg:maven/org.jenkins-ci.plugins/pipeline-githubnotify-step

Vulnerabilities (2)

  • CVE-2020-2117Feb 12, 2020
    affected < 1.0.5fixed 1.0.5

    A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored

  • CVE-2020-2116Feb 12, 2020
    affected < 1.0.5fixed 1.0.5

    A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.