Filtered by vendor Jenkins Subscriptions
Filtered by product Openshift Pipeline Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-64143 1 Jenkins 1 Openshift Pipeline 2025-10-30 4.3 Medium
Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.
CVE-2020-2167 2 Jenkins, Redhat 2 Openshift Pipeline, Openshift 2024-11-21 8.8 High
Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.