CVE-2022-28157
https://notcve.org/view.php?id=CVE-2022-28157
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller via FTP to an attacker-specified FTP server. Jenkins Pipeline: Phoenix AutoTest Plugin versiones 1.3 y anteriores, permite a atacantes con permiso Item/Configure subir archivos arbitrarios desde el controlador Jenkins por medio de FTP a un servidor FTP especificado por el atacante • http://www.openwall.com/lists/oss-security/2022/03/29/1 https://www.jenkins.io/security/advisory/2022-03-29/#SECURITY-2684 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2022-28156
https://notcve.org/view.php?id=CVE-2022-28156
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to copy arbitrary files and directories from the Jenkins controller to the agent workspace. Jenkins Pipeline: Phoenix AutoTest Plugin versiones 1.3 y anteriores, permite a atacantes con permiso de Item/Configure copiar archivos y directorios arbitrarios desde el controlador Jenkins al espacio de trabajo del agente • http://www.openwall.com/lists/oss-security/2022/03/29/1 https://www.jenkins.io/security/advisory/2022-03-29/#SECURITY-2683 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2022-28155
https://notcve.org/view.php?id=CVE-2022-28155
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Jenkins Pipeline: Phoenix AutoTest Plugin versiones 1.3 y anteriores, no configura su analizador XML para evitar ataques de tipo XML external entity (XXE) • http://www.openwall.com/lists/oss-security/2022/03/29/1 https://www.jenkins.io/security/advisory/2022-03-29/#SECURITY-1897 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2022-28154
https://notcve.org/view.php?id=CVE-2022-28154
Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Jenkins Coverage/Complexity Scatter Plot Plugin versiones 1.1.1 y anteriores, no configura su parser XML para prevenir ataques de tipo XML external entity (XXE) • http://www.openwall.com/lists/oss-security/2022/03/29/1 https://www.jenkins.io/security/advisory/2022-03-29/#SECURITY-1899 • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2022-28153
https://notcve.org/view.php?id=CVE-2022-28153
Jenkins SiteMonitor Plugin 0.6 and earlier does not escape URLs of sites to monitor in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. Jenkins SiteMonitor Plugin versiones 0.6 y anteriores, no escapa de las URLs de los sitios a monitorizar en los tooltips, resultando en una vulnerabilidad de tipo Cross-site scripting (XSS) almacenada explotable por atacantes con permiso Item/Configure • http://www.openwall.com/lists/oss-security/2022/03/29/1 https://www.jenkins.io/security/advisory/2022-03-29/#SECURITY-1932 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •