Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Appspider MEDIUM 5.5
CVE-2020-2314

Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be …

Fix: after 1.0.12
Fix from $1,600 2020-11-04
Static Analysis Utilities MEDIUM 5.4
CVE-2020-2316

Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site script…

Fix: after 1.96
Fix from $1,600 2020-11-04
Findbugs MEDIUM 5.4
CVE-2020-2317

Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulner…

Fix: after 5.0.0
Fix from $1,600 2020-11-04
Active Directory CRITICAL 9.8
CVE-2020-2300

Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log i…

Fix: after 2.19
Fix from $2,300 2020-11-04
Active Directory CRITICAL 9.8
CVE-2020-2301

Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that u…

Fix: after 2.19
Fix from $2,300 2020-11-04
Subversion MEDIUM 6.5
CVE-2020-2304

Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2.13.1
Fix from $1,600 2020-11-04
Mercurial MEDIUM 6.5
CVE-2020-2305

Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2.11
Fix from $1,600 2020-11-04
Active Directory CRITICAL 9.8
CVE-2020-2299

Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password.

Fix: after 2.19
Fix from $2,300 2020-11-04
Nerrvana MEDIUM 6.5
CVE-2020-2298

Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.02.06
Fix from $1,600 2020-10-08
Role Based Authorization Strategy HIGH 8.8
CVE-2020-2286

Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when the configuration is changed, r…

Fix: after 3.0
Fix from $1,950 2020-10-08
Persona MEDIUM 6.5
CVE-2020-2293

Jenkins Persona Plugin 2.4 and earlier allows users with Overall/Read permission to read arbitrary files on the Jenkins controller.

Fix: after 2.4
Fix from $1,600 2020-10-08
Active Choices MEDIUM 5.4
CVE-2020-2289

Jenkins Active Choices Plugin 2.4 and earlier does not escape the name and description of build parameters, resulting in a stored cross-site scriptin…

Fix: after 2.4
Fix from $1,600 2020-10-08
Active Choices MEDIUM 5.4
CVE-2020-2290

Jenkins Active Choices Plugin 2.4 and earlier does not escape some return values of sandboxed scripts for Reactive Reference Parameters, resulting in…

Fix: after 2.4
Fix from $1,600 2020-10-08
Release MEDIUM 5.4
CVE-2020-2292

Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cross-site scripting (XSS) vuln…

Fix: after 2.10.2
Fix from $1,600 2020-10-08
Audit Trail MEDIUM 5.3
CVE-2020-2287

Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework…

Fix: after 3.6
Fix from $1,600 2020-10-08
Audit Trail MEDIUM 5.3
CVE-2020-2288

In Jenkins Audit Trail Plugin 3.6 and earlier, the default regular expression pattern could be bypassed in many cases by adding a suffix to the URL t…

Fix: after 3.6
Fix from $1,600 2020-10-08
Script Security CRITICAL 9.9
CVE-2020-2279

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to define sandboxed scripts to pro…

Fix: after 1.74
Fix from $2,300 2020-09-23
Warnings HIGH 8.8
CVE-2020-2280

A cross-site request forgery (CSRF) vulnerability in Jenkins Warnings Plugin 5.0.1 and earlier allows attackers to execute arbitrary code.

Fix: after 5.0.1
Fix from $1,950 2020-09-23
Liquibase Runner HIGH 7.1
CVE-2020-2284

Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.4.5
Fix from $1,950 2020-09-23
Lockable Resources MEDIUM 5.4
CVE-2020-2281

A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers to reserve, unreserve, unlock…

Fix: after 2.8
Fix from $1,600 2020-09-23
Liquibase Runner MEDIUM 5.4
CVE-2020-2283

Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability …

Fix: after 1.4.5
Fix from $1,600 2020-09-23
MongoDB HIGH 8.8
CVE-2020-2268

A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain access to some metadata of any a…

Fix: after 1.3
Fix from $1,950 2020-09-16
Selection Tasks HIGH 8.8
CVE-2020-2276

Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing attackers with Job/Configure per…

Fix: after 1.0
Fix from $1,950 2020-09-16
Copy Data To Workspace MEDIUM 6.5
CVE-2020-2275

Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, a…

Fix: after 1.0
Fix from $1,600 2020-09-16
Storable Configs MEDIUM 6.5
CVE-2020-2277

Jenkins Storable Configs Plugin 1.0 and earlier allows users with Job/Read permission to read arbitrary files on the Jenkins controller.

Fix: after 1.0
Fix from $1,600 2020-09-16
Storable Configs MEDIUM 6.5
CVE-2020-2278

Jenkins Storable Configs Plugin 1.0 and earlier does not restrict the user-specified file name, allowing attackers with Job/Configure permission to r…

Fix: after 1.0
Fix from $1,600 2020-09-16
Elastest MEDIUM 5.5
CVE-2020-2274

Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it …

Fix: after 1.2.1
Fix from $1,600 2020-09-16
Chosen Views Tabbar MEDIUM 5.4
CVE-2020-2269

Jenkins chosen-views-tabbar Plugin 1.2 and earlier does not escape view names in the dropdown to select views, resulting in a stored cross-site scrip…

Fix: after 1.2
Fix from $1,600 2020-09-16
Clearcase Release MEDIUM 5.4
CVE-2020-2270

Jenkins ClearCase Release Plugin 0.3 and earlier does not escape the composite baseline in badge tooltip, resulting in a stored cross-site scripting …

Fix: after 0.3
Fix from $1,600 2020-09-16
Locked Files Report MEDIUM 5.4
CVE-2020-2271

Jenkins Locked Files Report Plugin 1.6 and earlier does not escape locked files' names in tooltips, resulting in a stored cross-site scripting (XSS) …

Fix: after 1.6
Fix from $1,600 2020-09-16