General-Purpose System Vulnerabilities
Vulnerabilities related to traditional IT systems, servers, and desktop applications.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2020-2105 | REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks. | Medium (5.4) | 2020-01-29 | General Purpose |
| CVE-2020-2104 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage ch… | Medium (4.3) | 2020-01-29 | General Purpose |
| CVE-2020-2103 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI … | Medium (5.4) | 2020-01-29 | General Purpose |
| CVE-2020-2102 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC. | Medium (5.3) | 2020-01-29 | General Purpose |
| CVE-2020-2101 | Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating conne… | Medium (5.3) | 2020-01-29 | General Purpose |