Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Dbcharts
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25206 1 Jenkins 1 Dbcharts 2022-02-23 6.5 MEDIUM 8.8 HIGH
A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified database via JDBC using attacker-specified credentials.
CVE-2022-25205 1 Jenkins 1 Dbcharts 2022-02-23 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine if a class is available in the Jenkins instance.