VYPR

Collabnet

by Jenkins Project

CVEs (2)

  • CVE-2018-1000605HigJun 26, 2018
    risk 0.48cvss 7.4epss 0.01

    A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidator.java that allows attackers to impersonate any service that Jenkins connects to.

  • CVE-2022-38665MedAug 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.