4.3

CVSS3.1

CVE-2025-64146 -

Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.3

CVSS3.1

CVE-2025-64145 -

Jenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.3

CVSS3.1

CVE-2025-64144 -

Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.3

CVSS3.1

CVE-2025-64143 -

Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.3

CVSS3.1

CVE-2025-64142 -

A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.3

CVSS3.1

CVE-2025-64141 -

A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

8.8

CVSS3.1

CVE-2025-64140 -

Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary shell commands.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Dec. 22, 2025, 3:18 p.m.

4.3

CVSS3.1

CVE-2025-64139 -

A missing permission check in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.3

CVSS3.1

CVE-2025-64138 -

A cross-site request forgery (CSRF) vulnerability in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

4.3

CVSS3.1

CVE-2025-64137 -

A missing permission check in Jenkins Themis Plugin 1.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.
Total resulsts: 349182
Page 3226 of 34,919
ยซ previous page ยป next page
Filters