VYPR

Liquibase Runner Plugin

by Jenkins Project

Source repositories

CVEs (3)

  • CVE-2020-2284HigSep 23, 2020
    risk 0.46cvss 7.1epss 0.01

    Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2283MedSep 23, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control changeset files evaluated by the plugin.

  • CVE-2020-2285MedSep 23, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.