Skip to main content

Vendor/product archive

jenkins / jira CVEs

Beta · best-effort

5 CVEs tagged to jenkins / jira1 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2023-49653

Published Nov 29, 2023

Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentia…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29041

Published Apr 12, 2022

Jenkins Jira Plugin 3.7 and earlier, except 3.6.1, does not escape the name and description of Jira Issue and Jira Release Version parameters on views displaying parameters, resul…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16541

Published Nov 21, 2019

Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and use credentials with System s…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000412

Published Jan 9, 2019

An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1