VYPR

Github Branch Source

by Jenkins Project

Source repositories

CVEs (8)

  • CVE-2017-1000091MedOct 5, 2017
    risk 0.41cvss 6.3epss 0.01

    GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan Credentials are correct). This functionality improperly checked permissions, allowing any user with Overall/Read access…

  • CVE-2024-23901MedJan 24, 2024
    risk 0.35cvss 6.5epss 0.00

    Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share a project, resulting in a crafted Pipeline being built by Jenkins during the next…

  • CVE-2026-57285MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configuration.

  • CVE-2026-42522MedApr 29, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.

  • CVE-2017-1000087MedOct 5, 2017
    risk 0.28cvss 4.3epss 0.01

    GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those…

  • CVE-2024-23903MedJan 24, 2024
    risk 0.27cvss 5.3epss 0.01

    Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

  • CVE-2024-23902MedJan 24, 2024
    risk 0.21cvss 4.3epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier allows attackers to connect to an attacker-specified URL.

  • CVE-2018-1000185MedJun 5, 2018
    risk 0.21cvss 4.3epss 0.01

    A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.