Vulnerabilities
Vulnerable Software
Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files. These values are stored unencrypted and can be viewed by users with access to the Jenkins controller file system.
CVSS Score
5.5
EPSS Score
0.009
Published
2022-03-15
Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.
CVSS Score
6.5
EPSS Score
0.0
Published
2017-10-05


Contact Us

Shodan ® - All rights reserved