CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they're written to the build log. |
1Jenkins 1Config File Provider Jun 17, 2026 Apr 21, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs. |
1Jenkins 1Config File Provider Jun 17, 2026 Apr 21, 2021 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID. |
1Jenkins 1Config File Provider Jun 17, 2026 Apr 21, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials...Show more |
1Jenkins 1Config File Provider Jun 17, 2026 Apr 21, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
2Jenkins Redhat2Config File Provider Openshift Container PlatformJun 17, 2026 Feb 6, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configu...Show more |
1Jenkins 1Config File Provider Nov 21, 2024 Jan 9, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigFileAction.java that allows creating and editing configuration file defi...Show more |
1Jenkins 1Config File Provider Nov 21, 2024 Jan 9, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert ar...Show more |
1Jenkins 1Config File Provider May 13, 2026 Oct 5, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs directly that allowed...Show more |