Skip to main content

Vendor/product archive

jenkins / team_concert CVEs

Beta · best-effort

4 CVEs tagged to jenkins / team_concert0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2023-3315

Published Jun 19, 2023

Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16567

Published Dec 17, 2019

A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentia…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16566

Published Dec 17, 2019

A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-sp…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16565

Published Dec 17, 2019

A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified crede…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1