CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Jenkins 1Cloudbees Aws Credentials Jun 17, 2026 Mar 15, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token. |
1Jenkins 1Cloudbees Aws Credentials Jun 17, 2026 Mar 15, 2022 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-spe...Show more |
1Jenkins 1Cloudbees Aws Credentials Jun 17, 2026 Mar 18, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of AWS cre...Show more |