Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Icescrum
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-10442 1 Jenkins 1 Icescrum 2020-10-01 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
CVE-2019-10441 1 Jenkins 1 Icescrum 2019-10-21 4.3 MEDIUM 4.3 MEDIUM
A cross-site request forgery vulnerability in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials.