2.3
10 years ago
2 months ago
Known vulnerabilities in the net.gleske:jervis package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
net.gleske:jervis is a Self service Jenkins job generation using Jenkins Job DSL plugin groovy scripts. Reads .jervis.yml and generates a job in Jenkins. Affected versions of this package are vulnerable to Use of a Broken or Risky Cryptographic Algorithm due to improper padding of SHA-256 hex strings in the How to fix Use of a Broken or Risky Cryptographic Algorithm? Upgrade | [,2.2) |
net.gleske:jervis is a Self service Jenkins job generation using Jenkins Job DSL plugin groovy scripts. Reads .jervis.yml and generates a job in Jenkins. Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature in the JWT verification process. An attacker can bypass signature validation by crafting a JWT with an unexpected algorithm in the header, potentially allowing unauthorized access or actions. How to fix Improper Verification of Cryptographic Signature? Upgrade | [,2.2) |
net.gleske:jervis is a Self service Jenkins job generation using Jenkins Job DSL plugin groovy scripts. Reads .jervis.yml and generates a job in Jenkins. Affected versions of this package are vulnerable to Use of a Broken or Risky Cryptographic Algorithm via the Note: This is only exploitable if consumers use the affected encryption methods directly, as the default implementation includes additional integrity checks and key protections. How to fix Use of a Broken or Risky Cryptographic Algorithm? Upgrade | [,2.2) |
net.gleske:jervis is a Self service Jenkins job generation using Jenkins Job DSL plugin groovy scripts. Reads .jervis.yml and generates a job in Jenkins. Affected versions of this package are vulnerable to Use of a Broken or Risky Cryptographic Algorithm in How to fix Use of a Broken or Risky Cryptographic Algorithm? Upgrade | [,2.2) |
net.gleske:jervis is a Self service Jenkins job generation using Jenkins Job DSL plugin groovy scripts. Reads .jervis.yml and generates a job in Jenkins. Affected versions of this package are vulnerable to Use of a Broken or Risky Cryptographic Algorithm via the How to fix Use of a Broken or Risky Cryptographic Algorithm? Upgrade | [,2.2) |
net.gleske:jervis is a Self service Jenkins job generation using Jenkins Job DSL plugin groovy scripts. Reads .jervis.yml and generates a job in Jenkins. Affected versions of this package are vulnerable to Insecure Randomness via the How to fix Insecure Randomness? Upgrade | [,2.2) |
net.gleske:jervis is a Self service Jenkins job generation using Jenkins Job DSL plugin groovy scripts. Reads .jervis.yml and generates a job in Jenkins. Affected versions of this package are vulnerable to Inadequate Encryption Strength in the How to fix Inadequate Encryption Strength? Upgrade | [,2.2) |