Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jenkins MEDIUM 5.3
CVE-2020-2102

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.

Fix: after 2.218
Fix from $1,600 2020-01-29
Cloudbees HIGH 7.5
CVE-2015-1809

XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files …

Fix: 1.596.1 / 1.600+
Fix from $1,950 2020-01-15
Cloudbees HIGH 7.5
CVE-2015-1811

XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files …

Fix: 1.596.1 / 1.600+
Fix from $1,950 2020-01-15
Sounds HIGH 8.8
CVE-2020-2098

A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user a…

Fix: after 0.5
Fix from $1,950 2020-01-15
Amazon Ec2 HIGH 8.8
CVE-2020-2090

A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to an attacker-specified URL wit…

Fix: after 1.47
Fix from $1,950 2020-01-15
Robot Framework HIGH 8.8
CVE-2020-2092

Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with …

Fix: after 2.0.0
Fix from $1,950 2020-01-15
Health Advisor By Cloudbees HIGH 8.8
CVE-2020-2093

A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers to send an email with fixed…

Fix: after 3.0
Fix from $1,950 2020-01-15
Sounds HIGH 8.8
CVE-2020-2097

Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read acc…

Fix: after 0.5
Fix from $1,950 2020-01-15
Amazon Ec2 HIGH 8.1
CVE-2020-2091

A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec…

Fix: after 1.47
Fix from $1,950 2020-01-15
Gitlab Hook MEDIUM 6.1
CVE-2020-2096EPSS 93%

Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.

Fix: after 1.4.2
Fix from $1,600 2020-01-15
Alauda Kubernetes Support HIGH 8.8
CVE-2019-16575

A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers to connect to an attacker-sp…

Fix: after 2.3.0
Fix from $1,950 2019-12-17
Alauda Devops Pipeline MEDIUM 6.5
CVE-2019-16574

A missing permission check in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers with Overall/Read permission to connect to an …

Fix: after 2.3.2
Fix from $1,600 2019-12-17
Alauda Kubernetes Support MEDIUM 6.5
CVE-2019-16576

A missing permission check in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers with Overall/Read permission to connect to a…

Fix: after 2.3.0
Fix from $1,600 2019-12-17
Alauda Devops Pipeline HIGH 8.8
CVE-2019-16573

A cross-site request forgery vulnerability in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers to connect to an attacker-spec…

Fix: after 2.3.2
Fix from $1,950 2019-12-17
Weibo MEDIUM 5.5
CVE-2019-16572

Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed…

Fix: after 1.0.1
Fix from $1,600 2019-12-17
Rapiddeploy HIGH 8.8
CVE-2019-16570

A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to an attacker-specified web ser…

Fix: after 4.1
Fix from $1,950 2019-12-17
Sctmexecutor MEDIUM 5.3
CVE-2019-16568

Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of the global configuration, as…

Fix: after 2.2
Fix from $1,600 2019-12-17
Team Concert HIGH 8.8
CVE-2019-16565

A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect to an attacker-specified URL …

Fix: after 1.3.0
Fix from $1,950 2019-12-17
Team Concert MEDIUM 6.5
CVE-2019-16566

A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-s…

Fix: after 1.3.0
Fix from $1,600 2019-12-17
Pipeline Aggregator View MEDIUM 5.4
CVE-2019-16564

Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a stored XSS vulnerability exploi…

Fix: after 1.8
Fix from $1,600 2019-12-17
Buildgraph View MEDIUM 5.4
CVE-2019-16562

Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the description of builds shown in its view, resulting in a stored XSS vulnerability e…

Fix: after 1.8
Fix from $1,600 2019-12-17
Mission Control MEDIUM 5.4
CVE-2019-16563

Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, resulting in a stored XSS vuln…

Fix: after 0.9.16
Fix from $1,600 2019-12-17
Websphere Deployer HIGH 8.8
CVE-2019-16560

A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to perform connection tests and de…

Fix: after 1.6.1
Fix from $1,950 2019-12-17
Websphere Deployer HIGH 7.1
CVE-2019-16561

Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for …

Fix: after 1.6.1
Fix from $1,950 2019-12-17
Websphere Deployer MEDIUM 5.4
CVE-2019-16559

A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection…

Fix: after 1.6.1
Fix from $1,600 2019-12-17
Spira Importer HIGH 8.2
CVE-2019-16558

Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.

Fix: after 3.2.3
Fix from $1,950 2019-12-17
Redgate Sql Change Automation MEDIUM 6.5
CVE-2019-16557

Jenkins Redgate SQL Change Automation Plugin 2.0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where the…

Fix: after 2.0.3
Fix from $1,600 2019-12-17
Build Failure Analyzer HIGH 8.8
CVE-2019-16553

A cross-site request forgery vulnerability in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers to have Jenkins evaluate a co…

Fix: after 1.24.1
Fix from $1,950 2019-12-17
Build Failure Analyzer MEDIUM 6.5
CVE-2019-16555

A user-supplied regular expression in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier was processed in a way that wasn't interruptible, allo…

Fix: after 1.24.1
Fix from $1,600 2019-12-17
Rundeck MEDIUM 6.5
CVE-2019-16556

Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins m…

Fix: after 3.6.5
Fix from $1,600 2019-12-17