Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Kubernetes Ci
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-10469 1 Jenkins 1 Kubernetes Ci 2019-10-24 4.0 MEDIUM 6.5 MEDIUM
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2019-10470 1 Jenkins 1 Kubernetes Ci 2019-10-24 4.0 MEDIUM 6.5 MEDIUM
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.