Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Maven HIGH 8.8
CVE-2019-16550

A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to ha…

Fix: after 0.16.1
Fix from $1,950 2019-12-17
Gerrit Trigger HIGH 8.8
CVE-2019-16551

A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers to connect to an attacker-specified H…

Fix: after 2.30.1
Fix from $1,950 2019-12-17
Gerrit Trigger MEDIUM 5.4
CVE-2019-16552

A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacke…

Fix: after 2.30.1
Fix from $1,600 2019-12-17
Maven HIGH 8.1
CVE-2019-16549

Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-m…

Fix: after 0.16.1
Fix from $1,950 2019-12-17
Jira CRITICAL 9.9
CVE-2019-16541

Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and…

Fix: after 3.0.10
Fix from $2,300 2019-11-21
Google Compute Engine HIGH 8.8
CVE-2019-16548

A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineCloud#doProvision could be used …

Fix: 4.2.0+
Fix from $1,950 2019-11-21
Support Core MEDIUM 6.5
CVE-2019-16539

A missing permission check in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete support bundles.

Fix: after 2.63
Fix from $1,600 2019-11-21
Support Core MEDIUM 6.5
CVE-2019-16540

A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete arbitrary file…

Fix: after 2.63
Fix from $1,600 2019-11-21
Anchore Container Image Scanner MEDIUM 6.5
CVE-2019-16542

Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where …

Fix: after 1.0.19
Fix from $1,600 2019-11-21
Google Compute Engine MEDIUM 5.9
CVE-2019-16546

Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by the plugin, enabling man-in-th…

Fix: 4.2.0+
Fix from $1,600 2019-11-21
Spira Importer MEDIUM 5.5
CVE-2019-16543

Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can …

Fix: after 3.2.2
Fix from $1,600 2019-11-21
Script Security HIGH 8.8
CVE-2019-16538

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closure…

Fix: after 1.67
Fix from $1,950 2019-11-21
Jenkins MEDIUM 6.1
CVE-2012-4441

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the …

Fix: 1.466.2 / 1.482+
Fix from $1,600 2019-11-18
Jenkins MEDIUM 6.1
CVE-2012-4440

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the …

Fix: 1.466.2 / 1.482+
Fix from $1,600 2019-11-18
Jenkins HIGH 8.8
CVE-2012-4438

Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execut…

Fix: 1.466.2 / 1.482+
Fix from $1,950 2019-11-18
Jenkins MEDIUM 6.1
CVE-2012-4439

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a c…

Fix: 1.466.2 / 1.482+
Fix from $1,600 2019-11-18
Libvirt Slaves HIGH 8.8
CVE-2019-10471

A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-specified SSH server using att…

Fix: after 1.8.5
Fix from $1,950 2019-10-23
Zulip HIGH 7.8
CVE-2019-10476

Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be view…

Fix: after 1.1.0
Fix from $1,950 2019-10-23
Kubernetes Ci MEDIUM 6.5
CVE-2019-10469

A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attac…

Fix: after 1.3
Fix from $1,600 2019-10-23
Kubernetes Ci MEDIUM 6.5
CVE-2019-10470

A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to en…

Fix: after 1.3
Fix from $1,600 2019-10-23
Libvirt Slaves MEDIUM 6.5
CVE-2019-10472

A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to an attacker-specified SSH ser…

Fix: after 1.8.5
Fix from $1,600 2019-10-23
Build Metrics MEDIUM 6.1
CVE-2019-10475EPSS 58%

A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web page…

Fix: after 1.3
Fix from $1,600 2019-10-23
Deploy Weblogic HIGH 8.8
CVE-2019-10464

A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-…

Fix: after 4.1
Fix from $1,950 2019-10-23
Kubernetes Ci HIGH 8.8
CVE-2019-10468

A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified…

Fix: after 1.3
Fix from $1,950 2019-10-23
Dynatrace Application Monitoring HIGH 8.1
CVE-2019-10462

A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an at…

Fix: after 2.1.3
Fix from $1,950 2019-10-23
360 Fireline HIGH 8.1
CVE-2019-10466

An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve externa…

Fix: after 1.7.2
Fix from $1,950 2019-10-23
Bitbucket Oauth HIGH 7.8
CVE-2019-10460

Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where…

Fix: after 0.9
Fix from $1,950 2019-10-23
Dynatrace Application Monitoring HIGH 7.8
CVE-2019-10461

Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configuration file on the Jenkins mast…

Fix: after 2.1.3
Fix from $1,950 2019-10-23
Mattermost Notification MEDIUM 6.5
CVE-2019-10459

Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in its global configuration file a…

Fix: after 2.7.0
Fix from $1,600 2019-10-23
Dynatrace Application Monitoring MEDIUM 6.5
CVE-2019-10463

A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permission to connect to an attacker…

Fix: after 2.1.4
Fix from $1,600 2019-10-23