Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Perfecto HIGH 8.8
CVE-2020-2261

Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitr…

Fix: after 1.17
Fix from $1,950 2020-09-16
Blue Ocean MEDIUM 6.5
CVE-2020-2254

Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/C…

Fix: after 1.23.2
Fix from $1,600 2020-09-16
Pipeline Maven Integration MEDIUM 5.4
CVE-2020-2256

Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting…

Fix: after 3.9.2
Fix from $1,600 2020-09-16
Validating String Parameter MEDIUM 5.4
CVE-2020-2257

Jenkins Validating String Parameter Plugin 2.4 and earlier does not escape various user-controlled fields, resulting in a stored cross-site scripting…

Fix: after 2.4
Fix from $1,600 2020-09-16
Computer Queue MEDIUM 5.4
CVE-2020-2259

Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vul…

Fix: after 1.5
Fix from $1,600 2020-09-16
Android Lint MEDIUM 5.4
CVE-2020-2262

Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vuln…

Fix: after 2.6
Fix from $1,600 2020-09-16
Radiator View MEDIUM 5.4
CVE-2020-2263

Jenkins Radiator View Plugin 1.29 and earlier does not escape the full name of the jobs in tooltips, resulting in a stored cross-site scripting (XSS)…

Fix: after 1.29
Fix from $1,600 2020-09-16
Custom Job Icon MEDIUM 5.4
CVE-2020-2264

Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vul…

Fix: after 0.2
Fix from $1,600 2020-09-16
Coverage\/complexity Scatter Plot MEDIUM 5.4
CVE-2020-2265

Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, resulting in a stored cross-sit…

Fix: after 1.1.1
Fix from $1,600 2020-09-16
Description Column MEDIUM 5.4
CVE-2020-2266

Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting in a stored cross-site scripti…

Fix: after 1.3
Fix from $1,600 2020-09-16
Valgrind HIGH 7.1
CVE-2020-2245

Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.28
Fix from $1,950 2020-09-01
Klocwork Analysis MEDIUM 6.5
CVE-2020-2247

Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2020.2.1
Fix from $1,600 2020-09-01
Soapui Pro Functional Testing MEDIUM 6.5
CVE-2020-2250

Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files on the Jenkins controller w…

Fix: after 1.3
Fix from $1,600 2020-09-01
Jsgames MEDIUM 6.1
CVE-2020-2248

Jenkins JSGames Plugin 0.2 and earlier evaluates part of a URL as code, resulting in a reflected cross-site scripting (XSS) vulnerability.

Fix: after 0.2
Fix from $1,600 2020-09-01
Valgrind MEDIUM 5.4
CVE-2020-2246

Jenkins Valgrind Plugin 0.28 and earlier does not escape content in Valgrind XML reports, resulting in a stored cross-site scripting (XSS) vulnerabil…

Fix: after 0.28
Fix from $1,600 2020-09-01
Database HIGH 8.8
CVE-2020-2240

A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to execute arbitrary SQL scripts.

Fix: after 1.6
Fix from $1,950 2020-09-01
Database HIGH 8.8
CVE-2020-2241

A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect to an attacker-specified dat…

Fix: after 1.6
Fix from $1,950 2020-09-01
Database MEDIUM 6.5
CVE-2020-2242

A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-…

Fix: after 1.6
Fix from $1,600 2020-09-01
Git Parameter MEDIUM 5.4
CVE-2020-2238

Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page, resulting in a stored cross…

Fix: after 0.9.12
Fix from $1,600 2020-09-01
Cadence Vmanager MEDIUM 5.4
CVE-2020-2243

Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vu…

Fix: after 3.0.4
Fix from $1,600 2020-09-01
Build Failure Analyzer MEDIUM 5.4
CVE-2020-2244

Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scrip…

Fix: after 1.27.0
Fix from $1,600 2020-09-01
Email Extension HIGH 7.5
CVE-2020-2232

Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form,…

Mitigation only
Fix from $1,950 2020-08-12
Pipeline Maven Integration MEDIUM 6.5
CVE-2020-2233

A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to enumerate credenti…

Fix: after 3.8.2
Fix from $1,600 2020-08-12
Pipeline Maven Integration MEDIUM 6.5
CVE-2020-2234

A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to connect to an atta…

Fix: after 3.8.2
Fix from $1,600 2020-08-12
Pipeline Maven Integration MEDIUM 6.5
CVE-2020-2235

A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows attackers to connect to an at…

Fix: after 3.8.2
Fix from $1,600 2020-08-12
Jenkins MEDIUM 5.4
CVE-2020-2229EPSS 7%

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS…

Fix: after 2.251
Fix from $1,600 2020-08-12
Jenkins MEDIUM 5.4
CVE-2020-2230EPSS 83%

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scriptin…

Fix: after 2.251
Fix from $1,600 2020-08-12
Jenkins MEDIUM 5.4
CVE-2020-2231EPSS 5%

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', res…

Fix: after 2.251
Fix from $1,600 2020-08-12
Yet Another Build Visualizer MEDIUM 5.4
CVE-2020-2236

Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulner…

Fix: after 1.11
Fix from $1,600 2020-08-12
Gitlab Authentication HIGH 8.8
CVE-2020-2228

Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulner…

Fix: after 1.5
Fix from $1,950 2020-07-15