Maven package
org.sonatype.nexus.ci/nexus-jenkins-plugin
pkg:maven/org.sonatype.nexus.ci/nexus-jenkins-plugin
Vulnerabilities (4)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-50769 | — | < 3.18.1-01 | 3.18.1-01 | Dec 13, 2023 | Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in | ||
| CVE-2023-50768 | — | < 3.18.1-01 | 3.18.1-01 | Dec 13, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenk | ||
| CVE-2023-50767 | — | < 3.18.1-01 | 3.18.1-01 | Dec 13, 2023 | Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML. | ||
| CVE-2023-50766 | — | < 3.18.1-01 | 3.18.1-01 | Dec 13, 2023 | A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML. |
- CVE-2023-50769Dec 13, 2023affected < 3.18.1-01fixed 3.18.1-01
Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in
- CVE-2023-50768Dec 13, 2023affected < 3.18.1-01fixed 3.18.1-01
A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenk
- CVE-2023-50767Dec 13, 2023affected < 3.18.1-01fixed 3.18.1-01
Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.
- CVE-2023-50766Dec 13, 2023affected < 3.18.1-01fixed 3.18.1-01
A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.