Filtered by CWE-325
Total 22 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2017-2600 1 Jenkins 1 Jenkins 2019-10-09 N/A
In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of these nodes (SECURITY-343).
CVE-2017-2598 1 Jenkins 1 Jenkins 2019-10-09 N/A
Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).