Download
| Alert*
oval:org.secpod.oval:def:1801810
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents .Jenkins 2.274 and earlier, LTS 2 ... oval:org.secpod.oval:def:68956 The host is installed with Jenkins LTS through 2.263.1 or Jenkins rolling release through 2.274 and is prone to an untrusted data deserialisation vulnerability. A flaw is present in the application, which fails to properly handle REST API XML deserialization errors. Successful exploitation allows at ... oval:org.secpod.oval:def:68957 The host is installed with Jenkins LTS through 2.263.1 or Jenkins rolling release through 2.274 and is prone to an untrusted data deserialisation vulnerability. A flaw is present in the application, which fails to properly handle REST API XML deserialization errors. Successful exploitation allows at ... oval:org.secpod.oval:def:68928 The host is installed with Jenkins LTS through 2.263.1 or Jenkins rolling release through 2.274 and is prone to an untrusted data deserialisation vulnerability. A flaw is present in the application, which fails to properly handle REST API XML deserialization errors. Successful exploitation allows at ... oval:org.secpod.oval:def:68905 The host is installed with Jenkins LTS through 2.263.1 or Jenkins rolling release through 2.274 and is prone to an untrusted data deserialisation vulnerability. A flaw is present in the application, which fails to properly handle REST API XML deserialization errors. Successful exploitation allows at ... |