Vulnerability index

Browse CVEs

87 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2019-10277 Jenkins StarTeam Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended … Starteam Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10280 Jenkins Assembla Auth Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewe… Assembla Auth Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10281 Jenkins Relution Enterprise Appstore Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where the… Relution Enterprise Appstore Publisher Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10282 Jenkins Klaros-Testmanagement Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users w… Klaros Testmanagement Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10283 Jenkins mabl Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read… Mabl Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10284 Jenkins Diawi Upload Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Exten… Diawi Upload Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10285 Jenkins Minio Storage Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users … Minio Storage Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10286 Jenkins DeployHub Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended… Deployhub Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10288 Jenkins Jabber Server Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users … Jabber Server Mitigation only Fix from $1,9502019-04-04 MEDIUM 6.5 CVE-2019-1003098 A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method al… Openid Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-10278 A cross-site request forgery vulnerability in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method a… Jenkins Reviewbot Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-10279 A missing permission check in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers … Jenkins Reviewbot Mitigation only Fix from $1,6002019-04-04 HIGH 8.8 CVE-2019-1003066 Jenkins Bugzilla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with … Bugzilla Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003067 Jenkins Trac Publisher Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ext… Trac Publisher Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003068 Jenkins VMware vRealize Automation Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by us… Vmware Vrealize Automation Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003069 Jenkins Aqua Security Scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed b… Aqua Security Scanner Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003070 Jenkins veracode-scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by use… Veracode Scanner Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003071 Jenkins OctopusDeploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users … Octopusdeploy Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003072 Jenkins WildFly Deployer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with E… Wildfly Deployer Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003073 Jenkins VS Team Services Continuous Deployment Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be … Vs Team Services Continuous Deployment Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003074 Jenkins Hyper.sh Commons Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by use… Hyper.sh Commons Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003075 Jenkins Audit to Database Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by us… Audit To Database Mitigation only Fix from $1,9502019-04-04 MEDIUM 6.5 CVE-2019-1003076 A cross-site request forgery vulnerability in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form valida… Audit To Database Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003077 A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allo… Audit To Database Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003078 A cross-site request forgery vulnerability in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validat… Vmware Lab Manager Slaves Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003082 A cross-site request forgery vulnerability in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attack… Gearman Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003084 A cross-site request forgery vulnerability in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation … Zephyr Enterprise Test Management Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003086 A cross-site request forgery vulnerability in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form valida… Chef Sinatra Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003090 A cross-site request forgery vulnerability in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method… Soasta Cloudtest Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003092 A cross-site request forgery vulnerability in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows at… Nomad Mitigation only Fix from $1,6002019-04-04