Vulnerability index

Browse CVEs

87 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2019-1003051 Jenkins IRC Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with acces… Irc Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003052 Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can b… Aws Elastic Beanstalk Publisher Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003053 Jenkins HockeyApp Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended… Hockeyapp Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003054 Jenkins Jira Issue Updater Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with… Jira Issue Updater Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003055 Jenkins FTP publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users … Ftp Publisher Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003056 Jenkins WebSphere Deployer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with… Websphere Deployer Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003057 Jenkins Bitbucket Approve Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by us… Bitbucket Approve Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003060 Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by u… Official Owasp Zap Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003061 Jenkins jenkins-cloudformation-plugin Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by… Jenkins Cloudformation Plugin Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003062 Jenkins AWS CloudWatch Logs Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be … Aws Cloudwatch Logs Publisher Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003063 Jenkins Amazon SNS Build Notifier Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be view… Amazon Sns Build Notifier Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003064 Jenkins aws-device-farm Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by user… Aws Device Farm Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003065 Jenkins CloudShare Docker-Machine Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be view… Cloudshare Docker Machine Mitigation only Fix from $1,9502019-04-04 MEDIUM 6.5 CVE-2019-1003058 A cross-site request forgery vulnerability in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers to… Ftp Publisher Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003059 A missing permission check in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers with Overall/Read … Ftp Publisher Mitigation only Fix from $1,6002019-04-04 HIGH 8.5 CVE-2017-2650 It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access… Pipeline Classpath Step Mitigation only Fix from $1,9502018-07-27 HIGH 8.8 CVE-2018-1000610 A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java,… Configuration As Code Mitigation only Fix from $1,9502018-06-26 MEDIUM 6.5 CVE-2018-1000609 A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java th… Configuration As Code Mitigation only Fix from $1,6002018-06-26 HIGH 8.8 CVE-2017-1000107 Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations,… Script Security Mitigation only Fix from $1,9502017-10-05 HIGH 7.5 CVE-2017-1000108 The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has bee… Pipeline Input Step Mitigation only Fix from $1,9502017-10-05 MEDIUM 6.1 CVE-2017-1000109 The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vuln… Owasp Dependency Check Mitigation only Fix from $1,6002017-10-05 HIGH 8.0 CVE-2017-1000086 The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups,… Periodic Backup Mitigation only Fix from $1,9502017-10-05 HIGH 7.5 CVE-2017-1000092 Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at … Git Mitigation only Fix from $1,9502017-10-05 MEDIUM 6.5 CVE-2017-1000084 Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was run… Parameterized Trigger Mitigation only Fix from $1,6002017-10-05 MEDIUM 6.5 CVE-2017-1000095 The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, S… Script Security Mitigation only Fix from $1,6002017-10-05 MEDIUM 6.3 CVE-2017-1000091 GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to v… Github Branch Source Mitigation only Fix from $1,6002017-10-05 HIGH 7.3 CVE-2016-3102 The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that pe… Script Security Mitigation only Fix from $1,9502017-02-09