Latest jenkins google compute engine Vulnerabilities

A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attack...
maven/o.jenkins.plugins:neuvector-vulnerability-scanner<2.2
Jenkins Neuvector Vulnerability Scanner<2.2
Jenkins Jira<3.1.2
Jenkins Google Compute Engine<4.551.0
Jenkins Matlab<2.11.1
Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on...
Jenkins Google Compute Engine<4.3.17.1
maven/org.jenkins-ci.plugins:google-compute-engine>=4.5<4.551.v5a
maven/org.jenkins-ci.plugins:google-compute-engine<4.3.17.1
Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.xml files on the Jenkins controller where they can be viewed by users with Extended Read pe...
Jenkins Google Compute Engine<=4.3.8
Missing permission checks in various API endpoints in Jenkins Google Compute Engine Plugin 4.1.1 and earlier allow attackers with Overall/Read permission to obtain limited information about the plugin...
Jenkins Google Compute Engine<4.2.0
Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.
Jenkins Google Compute Engine<4.2.0
A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineCloud#doProvision could be used to provision new agents. Google Compute Engine Plug...
maven/org.jenkins-ci.plugins:google-compute-engine<=4.1.1
Jenkins Google Compute Engine<4.2.0

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203