Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Logstash MEDIUM 5.3
CVE-2020-2143

Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentiall…

Fix: after 2.3.1
Fix from $1,600 2020-03-09
Script Security HIGH 8.8
CVE-2020-2134

Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor…

Fix: after 1.70
Fix from $1,950 2020-03-09
Script Security HIGH 8.8
CVE-2020-2135

Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement Gr…

Fix: after 1.70
Fix from $1,950 2020-03-09
Cobertura HIGH 7.1
CVE-2020-2138

Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.15
Fix from $1,950 2020-03-09
Git MEDIUM 5.4
CVE-2020-2136

Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a…

Fix: after 4.2.0
Fix from $1,600 2020-03-09
Eagle Tester MEDIUM 6.5
CVE-2020-2129

Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be vi…

Fix: after 1.0.9
Fix from $1,600 2020-02-12
Harvest Scm MEDIUM 6.5
CVE-2020-2130

Jenkins Harvest SCM Plugin 0.5.1 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be vie…

Fix: after 0.5.1
Fix from $1,600 2020-02-12
Harvest Scm MEDIUM 6.5
CVE-2020-2131

Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by u…

Fix: after 0.5.1
Fix from $1,600 2020-02-12
Parasoft Environment Manager MEDIUM 6.5
CVE-2020-2132

Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can…

Fix: after 2.14
Fix from $1,600 2020-02-12
Applatix MEDIUM 6.5
CVE-2020-2133

Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users w…

Fix: after 1.1
Fix from $1,600 2020-02-12
Nunit HIGH 8.8
CVE-2020-2115

Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.25
Fix from $1,950 2020-02-12
Pipeline Github Notify Step HIGH 8.8
CVE-2020-2116

A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker…

Fix: after 1.0.4
Fix from $1,950 2020-02-12
Fitnesse HIGH 8.8
CVE-2020-2120

Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.30
Fix from $1,950 2020-02-12
Google Kubernetes Engine HIGH 8.8
CVE-2020-2121

Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulti…

Fix: after 0.8.0
Fix from $1,950 2020-02-12
Radargun HIGH 8.8
CVE-2020-2123

Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote cod…

Fix: after 1.7
Fix from $1,950 2020-02-12
Brakeman MEDIUM 5.4
CVE-2020-2122

Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site …

Fix: after 0.12
Fix from $1,600 2020-02-12
Azure Ad MEDIUM 5.3
CVE-2020-2119

Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentiall…

Fix: after 1.1.2
Fix from $1,600 2020-02-12
Pipeline\ HIGH 8.8
CVE-2020-2109

Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter expressions in CPS-transformed m…

Fix: after 2.78
Fix from $1,950 2020-02-12
Script Security HIGH 8.8
CVE-2020-2110

Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST trans…

Fix: after 1.69
Fix from $1,950 2020-02-12
S3 Publisher HIGH 7.5
CVE-2020-2114

Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, poten…

Fix: after 0.11.4
Fix from $1,950 2020-02-12
Subversion MEDIUM 5.4
CVE-2020-2111

Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting i…

Fix: after 2.13.0
Fix from $1,600 2020-02-12
Git Parameter MEDIUM 5.4
CVE-2020-2112

Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulner…

Fix: after 0.9.11
Fix from $1,600 2020-02-12
Git Parameter MEDIUM 5.4
CVE-2020-2113

Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnera…

Fix: after 0.9.11
Fix from $1,600 2020-02-12
Jenkins HIGH 8.6
CVE-2020-2099

Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthor…

Fix: after 2.218
Fix from $1,950 2020-01-29
Websphere Deployer HIGH 7.6
CVE-2020-2108

Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Jo…

Fix: after 1.6.1
Fix from $1,950 2020-01-29
Jenkins MEDIUM 5.8
CVE-2020-2100

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848.

Fix: after 2.218
Fix from $1,600 2020-01-29
Jenkins MEDIUM 5.4
CVE-2020-2103EPSS 7%

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.

Fix: after 2.218
Fix from $1,600 2020-01-29
Jenkins MEDIUM 5.4
CVE-2020-2105

REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.

Fix: after 2.218
Fix from $1,600 2020-01-29
Code Coverage Api MEDIUM 5.4
CVE-2020-2106

Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view, resulting in a stored XSS vu…

Fix: after 1.1.2
Fix from $1,600 2020-01-29
Jenkins MEDIUM 5.3
CVE-2020-2101

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could pot…

Fix: after 2.218
Fix from $1,600 2020-01-29