Vulnerability index

Browse CVEs

87 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Irc HIGH 8.8
CVE-2019-1003051

Jenkins IRC Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with acces…

Mitigation only
Fix from $1,950 2019-04-04
Aws Elastic Beanstalk Publisher HIGH 8.8
CVE-2019-1003052

Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can b…

Mitigation only
Fix from $1,950 2019-04-04
Hockeyapp HIGH 8.8
CVE-2019-1003053

Jenkins HockeyApp Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended…

Mitigation only
Fix from $1,950 2019-04-04
Jira Issue Updater HIGH 8.8
CVE-2019-1003054

Jenkins Jira Issue Updater Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with…

Mitigation only
Fix from $1,950 2019-04-04
Ftp Publisher HIGH 8.8
CVE-2019-1003055

Jenkins FTP publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users …

Mitigation only
Fix from $1,950 2019-04-04
Websphere Deployer HIGH 8.8
CVE-2019-1003056

Jenkins WebSphere Deployer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with…

Mitigation only
Fix from $1,950 2019-04-04
Bitbucket Approve HIGH 8.8
CVE-2019-1003057

Jenkins Bitbucket Approve Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by us…

Mitigation only
Fix from $1,950 2019-04-04
Official Owasp Zap HIGH 8.8
CVE-2019-1003060

Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by u…

Mitigation only
Fix from $1,950 2019-04-04
Jenkins Cloudformation Plugin HIGH 8.8
CVE-2019-1003061

Jenkins jenkins-cloudformation-plugin Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by…

Mitigation only
Fix from $1,950 2019-04-04
Aws Cloudwatch Logs Publisher HIGH 8.8
CVE-2019-1003062

Jenkins AWS CloudWatch Logs Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be …

Mitigation only
Fix from $1,950 2019-04-04
Amazon Sns Build Notifier HIGH 8.8
CVE-2019-1003063

Jenkins Amazon SNS Build Notifier Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be view…

Mitigation only
Fix from $1,950 2019-04-04
Aws Device Farm HIGH 8.8
CVE-2019-1003064

Jenkins aws-device-farm Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by user…

Mitigation only
Fix from $1,950 2019-04-04
Cloudshare Docker Machine HIGH 8.8
CVE-2019-1003065

Jenkins CloudShare Docker-Machine Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be view…

Mitigation only
Fix from $1,950 2019-04-04
Ftp Publisher MEDIUM 6.5
CVE-2019-1003058

A cross-site request forgery vulnerability in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers to…

Mitigation only
Fix from $1,600 2019-04-04
Ftp Publisher MEDIUM 6.5
CVE-2019-1003059

A missing permission check in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers with Overall/Read …

Mitigation only
Fix from $1,600 2019-04-04
Pipeline Classpath Step HIGH 8.5
CVE-2017-2650

It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access…

Mitigation only
Fix from $1,950 2018-07-27
Configuration As Code HIGH 8.8
CVE-2018-1000610

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java,…

Mitigation only
Fix from $1,950 2018-06-26
Configuration As Code MEDIUM 6.5
CVE-2018-1000609

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java th…

Mitigation only
Fix from $1,600 2018-06-26
Script Security HIGH 8.8
CVE-2017-1000107

Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations,…

Mitigation only
Fix from $1,950 2017-10-05
Pipeline Input Step HIGH 7.5
CVE-2017-1000108

The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has bee…

Mitigation only
Fix from $1,950 2017-10-05
Owasp Dependency Check MEDIUM 6.1
CVE-2017-1000109

The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vuln…

Mitigation only
Fix from $1,600 2017-10-05
Periodic Backup HIGH 8.0
CVE-2017-1000086

The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups,…

Mitigation only
Fix from $1,950 2017-10-05
Git HIGH 7.5
CVE-2017-1000092

Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at …

Mitigation only
Fix from $1,950 2017-10-05
Parameterized Trigger MEDIUM 6.5
CVE-2017-1000084

Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was run…

Mitigation only
Fix from $1,600 2017-10-05
Script Security MEDIUM 6.5
CVE-2017-1000095

The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, S…

Mitigation only
Fix from $1,600 2017-10-05
Github Branch Source MEDIUM 6.3
CVE-2017-1000091

GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to v…

Mitigation only
Fix from $1,600 2017-10-05
Script Security HIGH 7.3
CVE-2016-3102

The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that pe…

Mitigation only
Fix from $1,950 2017-02-09