CVE-2022-25191
https://notcve.org/view.php?id=CVE-2022-25191
Jenkins Agent Server Parameter Plugin 1.0 and earlier does not escape parameter names of agent server parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. Jenkins Agent Server Parameter Plugin versiones 1.0 y anteriores, no escapa a los nombres de los parámetros del servidor de agentes, resultando en una vulnerabilidad de tipo cross-site scripting (XSS) almacenada, que puede ser explotada por atacantes con permiso de Item/Configure • https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2268 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-25190
https://notcve.org/view.php?id=CVE-2022-25190
A missing permission check in Jenkins Conjur Secrets Plugin 1.0.11 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. Una falta de comprobación de permisos en Jenkins Conjur Secrets Plugin versiones 1.0.11 y anteriores, permite a atacantes con permiso Overall/Read enumerar los ID de las credenciales almacenadas en Jenkins • https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2350 • CWE-862: Missing Authorization •
CVE-2022-25189
https://notcve.org/view.php?id=CVE-2022-25189
Jenkins Custom Checkbox Parameter Plugin 1.1 and earlier does not escape parameter names of custom checkbox parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. Jenkins Custom Checkbox Parameter Plugin versiones 1.1 y anteriores, no escapa de los nombres de los parámetros de las casillas de verificación personalizadas, resultando en una vulnerabilidad de tipo cross-site scripting (XSS) almacenada que puede ser explotada por atacantes con permiso Item/Configure • https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2266 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-25188
https://notcve.org/view.php?id=CVE-2022-25188
Jenkins Fortify Plugin 20.2.34 and earlier does not sanitize the appName and appVersion parameters of its Pipeline steps, allowing attackers with Item/Configure permission to write or overwrite .xml files on the Jenkins controller file system with content not controllable by the attacker. Jenkins Fortify Plugin versiones 20.2.34 y anteriores, no sanea los parámetros appName y appVersion de sus pasos de Pipeline, permitiendo a atacantes con permiso Item/Configure escribir o sobrescribir archivos .xml en el sistema de archivos del controlador Jenkins con contenido no controlable por el atacante • http://www.openwall.com/lists/oss-security/2022/02/15/2 https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2214 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2022-25187
https://notcve.org/view.php?id=CVE-2022-25187
Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle. Jenkins Support Core Plugin versiones 2.79 y anteriores, no redacta determinada información confidencial en el paquete de soporte • https://www.jenkins.io/security/advisory/2022-02-15/#SECURITY-2186 • CWE-212: Improper Removal of Sensitive Information Before Storage or Transfer •