Skip to main content

Vendor/product archive

jenkins / pipeline_github_notify_step CVEs

Beta · best-effort

3 CVEs tagged to jenkins / pipeline_github_notify_step0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2020-2118

Published Feb 12, 2020

A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2117

Published Feb 12, 2020

A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL us…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2116

Published Feb 12, 2020

A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1