Skip to main content

Vendor/product archive

jenkins / config_file_provider CVEs

Beta · best-effort

9 CVEs tagged to jenkins / config_file_provider0 Critical, 3 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2023-40339

Published Aug 16, 2023

Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they're written…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21645

Published Apr 21, 2021

Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configurati…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21644

Published Apr 21, 2021

A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attac…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21643

Published Apr 21, 2021

Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permissi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21642

Published Apr 21, 2021

Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000414

Published Jan 9, 2019

A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigFileAction.java that allows cre…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000413

Published Jan 9, 2019

A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000104

Published Oct 5, 2017

The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1