Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Liquibase Runner
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-2285 1 Jenkins 1 Liquibase Runner 2020-09-30 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVE-2020-2283 1 Jenkins 1 Liquibase Runner 2020-09-28 3.5 LOW 5.4 MEDIUM
Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control changeset files evaluated by the plugin.