Filtered by vendor Jenkins
                         Subscriptions
                    
                    
                
                        Filtered by product Octopusdeploy
                         Subscriptions
                    
                    
                
                    Total
                    2 CVE
                
            | CVE | Vendors | Products | Updated | CVSS v3.1 | 
|---|---|---|---|---|
| CVE-2019-1003071 | 1 Jenkins | 1 Octopusdeploy | 2024-11-21 | 8.8 High | 
| Jenkins OctopusDeploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | ||||
| CVE-2019-1003027 | 1 Jenkins | 1 Octopusdeploy | 2024-11-21 | N/A | 
| A server-side request forgery vulnerability exists in Jenkins OctopusDeploy Plugin 1.8.1 and earlier in OctopusDeployPlugin.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified URL and obtain the HTTP response code if successful, and exception error message otherwise. | ||||
                            
                                
                                
                                    Page 1 of 1.