Known vulnerabilities in Pipeline GitHub Notify Step

Vendor: Jenkins
Software CPE: cpe:2.3:a:jenkins:pipeline_github_notify_step:*:*:*:*:*:jenkins:*:*
Total vulnerabilities: 3
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 7.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Pipeline GitHub Notify Step Pipeline GitHub Notify Step is affected by 3 known vulnerabilities: 1 medium, 2 low Critical High Medium Low

Vulnerabilities (3)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU25289 - Exposure of sensitive information to an unauthorized actor
CVE-2020-2118
CWE-200 Low
No
No
1.0.5 13.02.2020 SB2020021309
#VU25287 - Improper Access Control
CVE-2020-2117
CWE-284 Medium
No
No
1.0.5 13.02.2020 SB2020021309
#VU25286 - Cross-Site Request Forgery (CSRF)
CVE-2020-2116
CWE-352 Low
No
No
1.0.5 13.02.2020 SB2020021309