Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jenkins MEDIUM 5.4
CVE-2020-2221

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a sto…

Fix: after 2.244
Fix from $1,600 2020-07-15
Jenkins MEDIUM 5.4
CVE-2020-2222

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored…

Fix: after 2.244
Fix from $1,600 2020-07-15
Jenkins MEDIUM 5.4
CVE-2020-2223

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build …

Fix: after 2.244
Fix from $1,600 2020-07-15
Matrix Project MEDIUM 5.4
CVE-2020-2224

Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, re…

Fix: after 1.16
Fix from $1,600 2020-07-15
Matrix Project MEDIUM 5.4
CVE-2020-2225

Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, re…

Fix: after 1.16
Fix from $1,600 2020-07-15
Matrix Authorization Strategy MEDIUM 5.4
CVE-2020-2226

Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-sit…

Fix: after 2.6.1
Fix from $1,600 2020-07-15
Deployer Framework MEDIUM 5.4
CVE-2020-2227

Jenkins Deployer Framework Plugin 1.2 and earlier does not escape the URL displayed in the build home page, resulting in a stored cross-site scriptin…

Fix: after 1.2
Fix from $1,600 2020-07-15
Jenkins MEDIUM 5.4
CVE-2020-2220

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scri…

Fix: after 2.244
Fix from $1,600 2020-07-15
Kubernetes Ci HIGH 8.8
CVE-2020-2211

Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types…

Fix: after 1.3
Fix from $1,950 2020-07-02
Zap Pipeline MEDIUM 5.4
CVE-2020-2214

Jenkins ZAP Pipeline Plugin 1.9 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, ar…

Fix: after 1.9
Fix from $1,600 2020-07-02
Link Column MEDIUM 5.4
CVE-2020-2219

Jenkins Link Column Plugin 1.0 and earlier does not filter URLs of links created by users with View/Configure permission, resulting in a stored cross…

Fix: after 1.0
Fix from $1,600 2020-07-02
Vncrecorder MEDIUM 6.1
CVE-2020-2206

Jenkins VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected …

Fix: after 1.25
Fix from $1,600 2020-07-02
Vncviewer MEDIUM 6.1
CVE-2020-2207

Jenkins VncViewer Plugin 1.7 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cro…

Fix: after 1.7
Fix from $1,600 2020-07-02
Sonargraph Integration MEDIUM 5.4
CVE-2020-2201

Jenkins Sonargraph Integration Plugin 3.0.0 and earlier does not escape the file path for the Log file field form validation, resulting in a stored c…

Fix: after 3.0.0
Fix from $1,600 2020-07-02
Fortify On Demand MEDIUM 5.4
CVE-2020-2204

A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to the glob…

Fix: after 5.0.1
Fix from $1,600 2020-07-02
Play Framework HIGH 8.8
CVE-2020-2200

Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the `play` command on the Jenkins master for a form validation endpoin…

Fix: after 1.0.2
Fix from $1,950 2020-06-03
Selenium HIGH 8.0
CVE-2020-2196

Jenkins Selenium Plugin 3.141.59 and earlier has no CSRF protection for its HTTP endpoints, allowing attackers to perform all administrative actions …

Fix: after 3.141.59
Fix from $1,950 2020-06-03
Project Inheritance MEDIUM 6.5
CVE-2020-2198

Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job confi…

Fix: after 19.08.02
Fix from $1,600 2020-06-03
Subversion Partial Release Manager MEDIUM 6.1
CVE-2020-2199EPSS 6%

Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form validation, r…

Fix: after 1.0.1
Fix from $1,600 2020-06-03
Self Organizing Swarm Modules MEDIUM 6.5
CVE-2020-2192

A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allows attackers to add or remove…

Fix: after 3.20
Fix from $1,600 2020-06-03
Script Security MEDIUM 5.4
CVE-2020-2190

Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the In-process Script Approval pag…

Fix: after 1.72
Fix from $1,600 2020-06-03
Echarts Api MEDIUM 5.4
CVE-2020-2193

Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the parser identifier when rendering charts, resulting in a stored cross-site scriptin…

Fix: after 4.7.0-3
Fix from $1,600 2020-06-03
Echarts Api MEDIUM 5.4
CVE-2020-2194

Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the display name of the builds in the trend chart, resulting in a stored cross-site sc…

Fix: after 4.7.0-3
Fix from $1,600 2020-06-03
Compact Columns MEDIUM 5.4
CVE-2020-2195

Jenkins Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips, resulting in a stored cross-site scripting vuln…

Fix: after 1.11
Fix from $1,600 2020-06-03
Source Code Management Filter Jervis HIGH 8.8
CVE-2020-2189

Jenkins SCM Filter Jervis Plugin 0.2.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a…

Fix: after 0.2.1
Fix from $1,950 2020-05-06
Credentials Binding MEDIUM 6.5
CVE-2020-2181

Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no …

Fix: after 1.22
Fix from $1,600 2020-05-06
Copy Artifact MEDIUM 6.5
CVE-2020-2183

Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifacts from jobs they have no perm…

Fix: after 1.43.1
Fix from $1,600 2020-05-06
Amazon Ec2 MEDIUM 5.6
CVE-2020-2185

Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the-middle attacks.

Fix: after 1.50.1
Fix from $1,600 2020-05-06
Amazon Ec2 MEDIUM 5.6
CVE-2020-2187

Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-…

Fix: after 1.50.1
Fix from $1,600 2020-05-06
Yaml Axis HIGH 8.8
CVE-2020-2179

Jenkins Yaml Axis Plugin 0.2.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote …

Fix: after 0.2.0
Fix from $1,950 2020-04-16