Vulnerability index

Browse CVEs

87 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Starteam HIGH 8.8
CVE-2019-10277

Jenkins StarTeam Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended …

Mitigation only
Fix from $1,950 2019-04-04
Assembla Auth HIGH 8.8
CVE-2019-10280

Jenkins Assembla Auth Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewe…

Mitigation only
Fix from $1,950 2019-04-04
Relution Enterprise Appstore Publisher HIGH 8.8
CVE-2019-10281

Jenkins Relution Enterprise Appstore Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where the…

Mitigation only
Fix from $1,950 2019-04-04
Klaros Testmanagement HIGH 8.8
CVE-2019-10282

Jenkins Klaros-Testmanagement Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users w…

Mitigation only
Fix from $1,950 2019-04-04
Mabl HIGH 8.8
CVE-2019-10283

Jenkins mabl Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read…

Mitigation only
Fix from $1,950 2019-04-04
Diawi Upload HIGH 8.8
CVE-2019-10284

Jenkins Diawi Upload Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Exten…

Mitigation only
Fix from $1,950 2019-04-04
Minio Storage HIGH 8.8
CVE-2019-10285

Jenkins Minio Storage Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users …

Mitigation only
Fix from $1,950 2019-04-04
Deployhub HIGH 8.8
CVE-2019-10286

Jenkins DeployHub Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended…

Mitigation only
Fix from $1,950 2019-04-04
Jabber Server HIGH 8.8
CVE-2019-10288

Jenkins Jabber Server Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users …

Mitigation only
Fix from $1,950 2019-04-04
Openid MEDIUM 6.5
CVE-2019-1003098

A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method al…

Mitigation only
Fix from $1,600 2019-04-04
Jenkins Reviewbot MEDIUM 6.5
CVE-2019-10278

A cross-site request forgery vulnerability in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method a…

Mitigation only
Fix from $1,600 2019-04-04
Jenkins Reviewbot MEDIUM 6.5
CVE-2019-10279

A missing permission check in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers …

Mitigation only
Fix from $1,600 2019-04-04
Bugzilla HIGH 8.8
CVE-2019-1003066

Jenkins Bugzilla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with …

Mitigation only
Fix from $1,950 2019-04-04
Trac Publisher HIGH 8.8
CVE-2019-1003067

Jenkins Trac Publisher Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ext…

Mitigation only
Fix from $1,950 2019-04-04
Vmware Vrealize Automation HIGH 8.8
CVE-2019-1003068

Jenkins VMware vRealize Automation Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by us…

Mitigation only
Fix from $1,950 2019-04-04
Aqua Security Scanner HIGH 8.8
CVE-2019-1003069

Jenkins Aqua Security Scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed b…

Mitigation only
Fix from $1,950 2019-04-04
Veracode Scanner HIGH 8.8
CVE-2019-1003070

Jenkins veracode-scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by use…

Mitigation only
Fix from $1,950 2019-04-04
Octopusdeploy HIGH 8.8
CVE-2019-1003071

Jenkins OctopusDeploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users …

Mitigation only
Fix from $1,950 2019-04-04
Wildfly Deployer HIGH 8.8
CVE-2019-1003072

Jenkins WildFly Deployer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with E…

Mitigation only
Fix from $1,950 2019-04-04
Vs Team Services Continuous Deployment HIGH 8.8
CVE-2019-1003073

Jenkins VS Team Services Continuous Deployment Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be …

Mitigation only
Fix from $1,950 2019-04-04
Hyper.sh Commons HIGH 8.8
CVE-2019-1003074

Jenkins Hyper.sh Commons Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by use…

Mitigation only
Fix from $1,950 2019-04-04
Audit To Database HIGH 8.8
CVE-2019-1003075

Jenkins Audit to Database Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by us…

Mitigation only
Fix from $1,950 2019-04-04
Audit To Database MEDIUM 6.5
CVE-2019-1003076

A cross-site request forgery vulnerability in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form valida…

Mitigation only
Fix from $1,600 2019-04-04
Audit To Database MEDIUM 6.5
CVE-2019-1003077

A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allo…

Mitigation only
Fix from $1,600 2019-04-04
Vmware Lab Manager Slaves MEDIUM 6.5
CVE-2019-1003078

A cross-site request forgery vulnerability in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validat…

Mitigation only
Fix from $1,600 2019-04-04
Gearman MEDIUM 6.5
CVE-2019-1003082

A cross-site request forgery vulnerability in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attack…

Mitigation only
Fix from $1,600 2019-04-04
Zephyr Enterprise Test Management MEDIUM 6.5
CVE-2019-1003084

A cross-site request forgery vulnerability in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation …

Mitigation only
Fix from $1,600 2019-04-04
Chef Sinatra MEDIUM 6.5
CVE-2019-1003086

A cross-site request forgery vulnerability in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form valida…

Mitigation only
Fix from $1,600 2019-04-04
Soasta Cloudtest MEDIUM 6.5
CVE-2019-1003090

A cross-site request forgery vulnerability in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method…

Mitigation only
Fix from $1,600 2019-04-04
Nomad MEDIUM 6.5
CVE-2019-1003092

A cross-site request forgery vulnerability in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows at…

Mitigation only
Fix from $1,600 2019-04-04