Skip to main content

Vendor/product archive

jenkins / liquibase_runner CVEs

Beta · best-effort

4 CVEs tagged to jenkins / liquibase_runner0 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2020-2285

Published Sep 23, 2020

A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2284

Published Sep 23, 2020

Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2283

Published Sep 23, 2020

Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000146

Published Apr 5, 2018

An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1