VYPR

Communications Cloud Native Core Automated Test Suite

by Oracle Corporation

CVEs (50)

  • CVE-2019-10383MedAug 28, 2019
    risk 0.24cvss 4.8epss 0.01

    A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.

  • CVE-2022-20614MedJan 12, 2022
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

  • CVE-2022-20613MedJan 12, 2022
    risk 0.21cvss 4.3epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

  • CVE-2022-20612MedJan 12, 2022
    risk 0.21cvss 4.3epss 0.02

    A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.

  • CVE-2018-1999004MedJul 23, 2018
    risk 0.21cvss 4.3epss 0.01

    A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches.

  • CVE-2018-1999003MedJul 23, 2018
    risk 0.21cvss 4.3epss 0.01

    A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.

  • CVE-2018-1000195MedJun 5, 2018
    risk 0.21cvss 4.3epss 0.02

    A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn whether the response is…

  • CVE-2018-1000193MedJun 5, 2018
    risk 0.21cvss 4.3epss 0.01

    A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as…

  • CVE-2018-1000192MedJun 5, 2018
    risk 0.21cvss 4.3epss 0.01

    A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.

  • CVE-2021-29921CriMay 6, 2021
    risk 0.01cvss 9.8epss 0.07

    In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

Page 3 of 3