Vulnerability index

Browse CVEs

1,246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Enterprise CRITICAL 9.8
CVE-2019-11402

In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format.

Fix: 2018.5.3+
Fix from $2,300 2019-04-22
Jenkins Operations Center CRITICAL 9.8
CVE-2019-11350

CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the proxy co…

Mitigation only
Fix from $2,300 2019-04-19
Jira Ext HIGH 8.8
CVE-2019-10302

Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be vie…

Fix: after 0.8
Fix from $1,950 2019-04-18
Azure Publishersettings Credentials HIGH 8.8
CVE-2019-10303

Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master w…

Fix: after 1.2
Fix from $1,950 2019-04-18
Big Ip Local Traffic Manager CRITICAL 9.8
CVE-2019-6609

Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge …

Fix: 12.1.4.1 / 13.1.1.4+
Fix from $2,300 2019-04-15
Wonderware System Platform HIGH 8.8
CVE-2019-6525

AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node…

Fix: 2017+
Fix from $1,950 2019-04-11
Service Insight HIGH 7.8
CVE-2019-0032

A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authe…

Fix: 18.1r1+
Fix from $1,950 2019-04-10
Junos MEDIUM 6.8
CVE-2019-0035

When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be changed usi…

Mitigation only
Fix from $1,600 2019-04-10
Insightvm MEDIUM 6.5
CVE-2019-5615

Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Global Administrators and clear-te…

Fix: after 6.5.49
Fix from $1,600 2019-04-09
Nas326 Firmware HIGH 8.8
CVE-2019-10630

A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device.

Fix: after 5.21
Fix from $1,950 2019-04-09
Kmap HIGH 8.8
CVE-2019-10294

Jenkins Kmap Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read…

Mitigation only
Fix from $1,950 2019-04-04
Crittercism Dsym HIGH 8.8
CVE-2019-10295

Jenkins crittercism-dsym Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with E…

Mitigation only
Fix from $1,950 2019-04-04
Serena Sra Deploy HIGH 8.8
CVE-2019-10296

Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by us…

Mitigation only
Fix from $1,950 2019-04-04
Sametime HIGH 8.8
CVE-2019-10297

Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with …

Mitigation only
Fix from $1,950 2019-04-04
Koji HIGH 8.8
CVE-2019-10298

Jenkins Koji Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with acce…

Mitigation only
Fix from $1,950 2019-04-04
Cloudcoreo Deploytime HIGH 8.8
CVE-2019-10299

Jenkins CloudCoreo DeployTime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed b…

Mitigation only
Fix from $1,950 2019-04-04
Testfairy MEDIUM 6.5
CVE-2019-1003096

Jenkins TestFairy Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended…

Fix: after 4.16
Fix from $1,600 2019-04-04
Crowd Integration MEDIUM 6.5
CVE-2019-1003097

Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be v…

Fix: after 1.2
Fix from $1,600 2019-04-04
Starteam HIGH 8.8
CVE-2019-10277

Jenkins StarTeam Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended …

Mitigation only
Fix from $1,950 2019-04-04
Assembla Auth HIGH 8.8
CVE-2019-10280

Jenkins Assembla Auth Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewe…

Mitigation only
Fix from $1,950 2019-04-04
Relution Enterprise Appstore Publisher HIGH 8.8
CVE-2019-10281

Jenkins Relution Enterprise Appstore Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where the…

Mitigation only
Fix from $1,950 2019-04-04
Klaros Testmanagement HIGH 8.8
CVE-2019-10282

Jenkins Klaros-Testmanagement Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users w…

Mitigation only
Fix from $1,950 2019-04-04
Mabl HIGH 8.8
CVE-2019-10283

Jenkins mabl Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read…

Mitigation only
Fix from $1,950 2019-04-04
Diawi Upload HIGH 8.8
CVE-2019-10284

Jenkins Diawi Upload Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Exten…

Mitigation only
Fix from $1,950 2019-04-04
Minio Storage HIGH 8.8
CVE-2019-10285

Jenkins Minio Storage Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users …

Mitigation only
Fix from $1,950 2019-04-04
Deployhub HIGH 8.8
CVE-2019-10286

Jenkins DeployHub Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended…

Mitigation only
Fix from $1,950 2019-04-04
Youtrack Plugin HIGH 8.8
CVE-2019-10287

Jenkins youtrack-plugin Plugin 0.7.1 and older stored credentials unencrypted in its global configuration file on the Jenkins master where they could…

Fix: after 0.7.1
Fix from $1,950 2019-04-04
Jabber Server HIGH 8.8
CVE-2019-10288

Jenkins Jabber Server Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users …

Mitigation only
Fix from $1,950 2019-04-04
Netsparker Cloud Scan HIGH 8.8
CVE-2019-10291

Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older stored credentials unencrypted in its global configuration file on the Jenkins master where they…

Fix: after 1.1.5
Fix from $1,950 2019-04-04
Ecs Publisher MEDIUM 6.5
CVE-2019-1003045

A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, or local file system access to…

Fix: after 1.0.0
Fix from $1,600 2019-03-28