Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Build With Parameters MEDIUM 5.4
CVE-2021-21628EPSS 81%

Jenkins Build With Parameters Plugin 1.5 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XS…

Fix: after 1.5
Fix from $1,600 2021-03-30
Extra Columns MEDIUM 5.4
CVE-2021-21630EPSS 72%

Jenkins Extra Columns Plugin 1.22 and earlier does not escape parameter values in the build parameters column, resulting in a stored cross-site scrip…

Fix: after 1.22
Fix from $1,600 2021-03-30
Rest List Parameter MEDIUM 5.4
CVE-2021-21635EPSS 9%

Jenkins REST List Parameter Plugin 1.3.0 and earlier does not escape a parameter name reference in embedded JavaScript, resulting in a stored cross-s…

Fix: after 1.3.0
Fix from $1,600 2021-03-30
Libvirt Agents HIGH 8.8
CVE-2021-21627

A cross-site request forgery (CSRF) vulnerability in Jenkins Libvirt Agents Plugin 1.9.0 and earlier allows attackers to stop hypervisor domains.

Fix: after 1.9.0
Fix from $1,950 2021-03-18
Matrix Authorization Strategy MEDIUM 6.5
CVE-2021-21623

An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested …

Fix: after 2.6.5
Fix from $1,600 2021-03-18
Artifact Repository Parameter MEDIUM 5.4
CVE-2021-21622EPSS 9%

Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scr…

Fix: after 1.0.0
Fix from $1,600 2021-02-24
Support Core MEDIUM 5.3
CVE-2021-21621

Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (basic authentication details onl…

Fix: after 2.72
Fix from $1,600 2021-02-24
Configuration Slicing HIGH 8.8
CVE-2021-21617

A cross-site request forgery (CSRF) vulnerability in Jenkins Configuration Slicing Plugin 1.51 and earlier allows attackers to apply different slice …

Fix: after 1.51
Fix from $1,950 2021-02-24
Repository Connector MEDIUM 5.4
CVE-2021-21618EPSS 82%

Jenkins Repository Connector Plugin 2.0.2 and earlier does not escape parameter names and descriptions for past builds, resulting in a stored cross-s…

Fix: after 2.0.2
Fix from $1,600 2021-02-24
Claim MEDIUM 5.4
CVE-2021-21619EPSS 9%

Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scripting (XSS) vulnerability exploit…

Fix: after 2.18.1
Fix from $1,600 2021-02-24
Jenkins MEDIUM 5.3
CVE-2021-21615

Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to t…

Fix: 2.263.3 / 2.276+
Fix from $1,600 2021-01-26
Jenkins MEDIUM 6.1
CVE-2021-21610

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted preview of markup passed as …

Fix: after 2.274
Fix from $1,600 2021-01-13
Tics MEDIUM 6.1
CVE-2021-21613

Jenkins TICS Plugin 2020.3.0.6 and earlier does not escape TICS service responses, resulting in a cross-site scripting (XSS) vulnerability exploitabl…

Fix: after 2020.3.0.6
Fix from $1,600 2021-01-13
Tracetronic Ecu Test MEDIUM 5.5
CVE-2021-21612

Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller wher…

Fix: after 2.23.1
Fix from $1,600 2021-01-13
Bumblebee Hp Alm MEDIUM 5.5
CVE-2021-21614

Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where the…

Fix: after 4.1.5
Fix from $1,600 2021-01-13
Jenkins MEDIUM 5.4
CVE-2021-21611

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page, resulting in a sto…

Fix: after 2.274
Fix from $1,600 2021-01-13
Jenkins HIGH 8.0
CVE-2021-21604

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content …

Fix: after 2.274
Fix from $1,950 2021-01-13
Jenkins HIGH 8.0
CVE-2021-21605

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override …

Fix: after 2.274
Fix from $1,950 2021-01-13
Jenkins MEDIUM 6.5
CVE-2021-21602

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by fol…

Fix: after 2.274
Fix from $1,600 2021-01-13
Jenkins MEDIUM 6.5
CVE-2021-21607

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to r…

Fix: after 2.274
Fix from $1,600 2021-01-13
Jenkins MEDIUM 5.4
CVE-2021-21603

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vuln…

Fix: after 2.274
Fix from $1,600 2021-01-13
Jenkins MEDIUM 5.4
CVE-2021-21608

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnera…

Fix: after 2.274
Fix from $1,600 2021-01-13
Jenkins MEDIUM 5.3
CVE-2021-21609

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers…

Fix: after 2.274
Fix from $1,600 2021-01-13
Installation Manager Tool CRITICAL 9.8
CVE-2020-2320

Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.

Fix: after 2.1.3
Fix from $2,300 2020-12-03
Shelve Project HIGH 8.1
CVE-2020-2321

A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to shelve, unshelve, or delete a …

Fix: after 3.0
Fix from $1,950 2020-12-03
Cvs HIGH 7.5
CVE-2020-2324

Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2.16
Fix from $1,950 2020-12-03
Sqlplus Script Runner MEDIUM 6.5
CVE-2020-2312

Jenkins SQLPlus Script Runner Plugin 2.0.12 and earlier does not mask a password provided as command line argument in build logs.

Fix: after 2.0.12
Fix from $1,600 2020-11-04
Visualworks Store MEDIUM 6.5
CVE-2020-2315

Jenkins Visualworks Store Plugin 1.1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.1.3
Fix from $1,600 2020-11-04
Mail Commander MEDIUM 6.5
CVE-2020-2318

Jenkins Mail Commander Plugin for Jenkins-ci Plugin 1.0.0 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller …

Fix: after 1.0.0
Fix from $1,600 2020-11-04
Vmware Lab Manager Slaves MEDIUM 6.5
CVE-2020-2319

Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller wher…

Fix: after 0.2.8
Fix from $1,600 2020-11-04