Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Fortify On Demand
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-2203 1 Jenkins 1 Fortify On Demand 2020-07-16 4.3 MEDIUM 4.3 MEDIUM
A cross-site request forgery vulnerability in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.
CVE-2020-2204 1 Jenkins 1 Fortify On Demand 2020-07-15 5.5 MEDIUM 5.4 MEDIUM
A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.
CVE-2020-2202 1 Jenkins 1 Fortify On Demand 2020-07-15 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins Fortify on Demand Plugin 6.0.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.