Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Amazon Web Services Serverless Application Model HIGH 8.8
CVE-2020-2180

Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote co…

Fix: after 1.2.2
Fix from $1,950 2020-04-16
Parasoft Findings HIGH 7.1
CVE-2020-2178

Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 10.4.3
Fix from $1,950 2020-04-16
Code Coverage Api MEDIUM 6.5
CVE-2020-2172

Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.1.4
Fix from $1,600 2020-04-07
Awseb Deployment MEDIUM 6.1
CVE-2020-2174

Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output, resulting in a reflected…

Fix: after 0.3.19
Fix from $1,600 2020-04-07
Gatling MEDIUM 5.4
CVE-2020-2173

Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports served by the plugin, resulting …

Fix: after 1.2.7
Fix from $1,600 2020-04-07
Fitnesse MEDIUM 5.4
CVE-2020-2175

Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI, resulting in a stored cross…

Fix: after 1.31
Fix from $1,600 2020-04-07
Usemango Runner MEDIUM 5.4
CVE-2020-2176

Multiple form validation endpoints in Jenkins useMango Runner Plugin 1.4 and earlier do not escape values received from the useMango service, resulti…

Fix: after 1.4
Fix from $1,600 2020-04-07
Pipeline\ HIGH 8.8
CVE-2020-2166

Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in …

Fix: after 1.40
Fix from $1,950 2020-03-25
Openshift Pipeline HIGH 8.8
CVE-2020-2167

Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in…

Fix: after 1.0.56
Fix from $1,950 2020-03-25
Azure Container Service HIGH 8.8
CVE-2020-2168

Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resultin…

Fix: after 1.0.1
Fix from $1,950 2020-03-25
Rapiddeploy HIGH 8.8
CVE-2020-2171

Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 4.2
Fix from $1,950 2020-03-25
Queue Cleanup MEDIUM 6.1
CVE-2020-2169

A form validation endpoint in Jenkins Queue cleanup Plugin 1.3 and earlier does not properly escape a query parameter displayed in an error message, …

Fix: after 1.3
Fix from $1,600 2020-03-25
Jenkins MEDIUM 5.4
CVE-2020-2161

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions o…

Fix: after 2.227
Fix from $1,600 2020-03-25
Jenkins MEDIUM 5.4
CVE-2020-2162

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, res…

Fix: after 2.227
Fix from $1,600 2020-03-25
Jenkins MEDIUM 5.4
CVE-2020-2163

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerabi…

Fix: after 2.227
Fix from $1,600 2020-03-25
Rapiddeploy MEDIUM 5.4
CVE-2020-2170

Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote server, resulting in a store…

Fix: after 4.2
Fix from $1,600 2020-03-25
Jenkins HIGH 8.8
CVE-2020-2160

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that all…

Fix: after 2.227
Fix from $1,950 2020-03-25
Literate HIGH 8.8
CVE-2020-2158

Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote cod…

Fix: after 1.0
Fix from $1,950 2020-03-09
Cryptomove HIGH 8.8
CVE-2020-2159

Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the…

Fix: after 0.1.33
Fix from $1,950 2020-03-09
Subversion Release Manager MEDIUM 6.1
CVE-2020-2152

Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation, resulting i…

Fix: after 1.2
Fix from $1,600 2020-03-09
Zephyr For Jira Test Management MEDIUM 5.5
CVE-2020-2154

Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configuration file on the Jenkins mas…

Fix: after 1.5
Fix from $1,600 2020-03-09
Repository Connector MEDIUM 5.3
CVE-2020-2149

Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form…

Fix: after 1.2.6
Fix from $1,600 2020-03-09
Sonar Quality Gates MEDIUM 5.3
CVE-2020-2150

Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form,…

Fix: after 1.3.1
Fix from $1,600 2020-03-09
Quality Gates MEDIUM 5.3
CVE-2020-2151

Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potenti…

Fix: after 2.5
Fix from $1,600 2020-03-09
Openshift Deployer MEDIUM 5.3
CVE-2020-2155

Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, …

Fix: after 1.2.0
Fix from $1,600 2020-03-09
Mac HIGH 7.4
CVE-2020-2146

Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.

Fix: after 1.1.0
Fix from $1,950 2020-03-09
Rundeck HIGH 7.1
CVE-2020-2144

Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 3.6.6
Fix from $1,950 2020-03-09
Cobertura MEDIUM 6.5
CVE-2020-2139

An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents…

Fix: after 1.15
Fix from $1,600 2020-03-09
Audit Trail MEDIUM 6.1
CVE-2020-2140EPSS 76%

Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cro…

Fix: after 3.2
Fix from $1,600 2020-03-09
Zephyr Enterprise Test Management MEDIUM 5.5
CVE-2020-2145

Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system.

Fix: after 1.9.1
Fix from $1,600 2020-03-09