CVE-2022-34784
https://notcve.org/view.php?id=CVE-2022-34784
Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Build/Update permission. Jenkins build-metrics Plugin 1.3 no escapa a la descripción de la construcción en una de sus visualizaciones, resultando en una vulnerabilidad de tipo cross-site scripting (XSS) almacenada explotable por atacantes con permiso Build/Update • https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-1118 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-34783
https://notcve.org/view.php?id=CVE-2022-34783
Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. Jenkins Plot Plugin versiones 2.1.10 y anteriores, no escapa de las descripciones de las parcelas, resultando en una vulnerabilidad de tipo cross-site scripting (XSS) almacenada, explotable por atacantes con permiso de Item/Configure • https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2220 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2022-34782
https://notcve.org/view.php?id=CVE-2022-34782
An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests. Una comprobación de permisos incorrecta en Jenkins requests-plugin Plugin versiones 2.2.16 y anteriores, permite a atacantes con permiso Overall/Read ver la lista de peticiones pendientes • https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2650 • CWE-863: Incorrect Authorization •
CVE-2022-34781
https://notcve.org/view.php?id=CVE-2022-34781
Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. Una falta de comprobación de permisos en Jenkins XebiaLabs XL Release Plugin versiones 22.0.0 y anteriores permite a atacantes con permiso Overall/Read conectarse a un servidor HTTP especificado por el atacante usando IDs de credenciales especificados por el atacante obtenidos a través de otro método, capturando credenciales almacenadas en Jenkins • https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2773%20%282%29 • CWE-862: Missing Authorization •
CVE-2022-34780
https://notcve.org/view.php?id=CVE-2022-34780
A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. Una vulnerabilidad de tipo cross-site request forgery (CSRF) en Jenkins XebiaLabs XL Release Plugin versiones 22.0.0 y anteriores, permite a atacantes conectarse a un servidor HTTP especificado por el atacante usando IDs de credenciales especificados por el atacante obtenidos mediante otro método, capturando credenciales almacenadas en Jenkins • https://www.jenkins.io/security/advisory/2022-06-30/#SECURITY-2773%20%282%29 • CWE-352: Cross-Site Request Forgery (CSRF) •