Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

R. Tyler Croy

Pesquisador deCloudBees, Inc.
#21050de 53,634
11.8CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2019-11308
4.3
2019-02-06
Jenkins · Jenkins Git Plugin · CVE-2019-1003010
Name of the Vulnerable Software and Affected Versions: Jenkins Git Plugin versions 3.9.1 and earlier Description: A cross-site request forgery issue exists that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record. This is due to a vulnerability in the src/main/java/hudson/plugins/git/GitTagAction.java file. Recommendations: For Jenkins Git Plugin versions 3.9.1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2017-10813
7.5
2017-10-04
Jenkins · Jenkins · CVE-2017-1000108
**Name of the Vulnerable Software and Affected Versions** Jenkins versions (affected versions not specified) **Description** The issue concerns the Pipeline: Input Step Plugin, which previously allowed users with Item/Read access to interact with the step. This has been changed to require Item/Build permission instead. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.