Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sonar Gerrit MEDIUM 6.5
CVE-2019-10467

Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Exten…

Fix: after 2.3
Fix from $1,600 2019-10-23
Puppet Enterprise Pipeline CRITICAL 9.9
CVE-2019-10458

Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to exec…

Fix: after 1.3.1
Fix from $2,300 2019-10-16
Delphix HIGH 7.8
CVE-2019-10453

Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with a…

Fix: after 2.0.4
Fix from $1,950 2019-10-16
Neoload HIGH 8.8
CVE-2019-10440

Jenkins NeoLoad Plugin 2.2.5 and earlier stored credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins m…

Fix: after 2.2.5
Fix from $1,950 2019-10-16
Icescrum HIGH 8.8
CVE-2019-10443

Jenkins iceScrum Plugin 1.1.4 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by …

Fix: after 1.1.4
Fix from $1,950 2019-10-16
Extensive Testing HIGH 8.8
CVE-2019-10448

Jenkins Extensive Testing Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with …

Mitigation only
Fix from $1,950 2019-10-16
Fortify On Demand HIGH 8.8
CVE-2019-10449

Jenkins Fortify on Demand Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with …

Fix: after 4.0.0
Fix from $1,950 2019-10-16
Cadence Vmanager HIGH 8.2
CVE-2019-10446

Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.

Fix: after 2.7.0
Fix from $1,950 2019-10-16
Bumblebee Hp Alm MEDIUM 6.5
CVE-2019-10444

Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connections to HP ALM.

Fix: after 4.1.3
Fix from $1,600 2019-10-16
Crx Content Package Deployer HIGH 8.8
CVE-2019-10437

A cross-site request forgery vulnerability in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers to connect to an attack…

Fix: after 1.8.1
Fix from $1,950 2019-10-16
Google Oauth Credentials MEDIUM 6.5
CVE-2019-10436

An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credenti…

Fix: after 0.9
Fix from $1,600 2019-10-16
Crx Content Package Deployer MEDIUM 6.5
CVE-2019-10438

A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers with Overall/Read permission to connect…

Fix: after 1.8.1
Fix from $1,600 2019-10-16
Sourcegear Vault HIGH 7.5
CVE-2019-10435

Jenkins SourceGear Vault Plugin transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exp…

Fix: after 1.1.1
Fix from $1,950 2019-10-01
Ldap Email HIGH 7.5
CVE-2019-10434

Jenkins LDAP Email Plugin transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in t…

Fix: after 0.8
Fix from $1,950 2019-10-01
Html Publisher MEDIUM 5.4
CVE-2019-10432

Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site…

Fix: after 1.20
Fix from $1,600 2019-10-01
Script Security CRITICAL 9.9
CVE-2019-10431

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constru…

Fix: after 1.64
Fix from $2,300 2019-10-01
Aqua Security Scanner HIGH 7.5
CVE-2019-10428

Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration …

Fix: after 3.0.17
Fix from $1,950 2019-09-25
Gitlab Logo MEDIUM 5.5
CVE-2019-10429

Jenkins GitLab Logo Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users wi…

Fix: after 1.0.3
Fix from $1,600 2019-09-25
Neuvector Vulnerability Scanner MEDIUM 5.5
CVE-2019-10430

Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master …

Fix: after 1.5
Fix from $1,600 2019-09-25
Aqua Microscanner MEDIUM 5.3
CVE-2019-10427

Jenkins Aqua MicroScanner Plugin 1.0.7 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form,…

Fix: after 1.0.7
Fix from $1,600 2019-09-25
Kubernetes Pipeline CRITICAL 9.9
CVE-2019-10417

Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary …

Fix: after 1.6
Fix from $2,300 2019-09-25
Kubernetes Pipeline CRITICAL 9.9
CVE-2019-10418

Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary …

Fix: after 1.6
Fix from $2,300 2019-09-25
Inedo Buildmaster HIGH 7.5
CVE-2019-10411

Jenkins Inedo BuildMaster Plugin 2.4.0 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form,…

Fix: after 2.4.0
Fix from $1,950 2019-09-25
Inedo Proget HIGH 7.5
CVE-2019-10412

Jenkins Inedo ProGet Plugin 1.2 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potent…

Fix: after 1.2
Fix from $1,950 2019-09-25
Data Theorem Mobile App Security MEDIUM 6.5
CVE-2019-10413

Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be v…

Fix: after 1.3
Fix from $1,600 2019-09-25
Git Changelog MEDIUM 6.5
CVE-2019-10414

Jenkins Git Changelog Plugin 2.17 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed…

Fix: after 2.17
Fix from $1,600 2019-09-25
Violation Comments To Gitlab MEDIUM 6.5
CVE-2019-10415

Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master wh…

Fix: after 2.28
Fix from $1,600 2019-09-25
Violation Comments To Gitlab MEDIUM 6.5
CVE-2019-10416

Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they …

Fix: after 2.28
Fix from $1,600 2019-09-25
Call Remote Job MEDIUM 6.5
CVE-2019-10422

Jenkins Call Remote Job Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ex…

Fix: after 1.0.21
Fix from $1,600 2019-09-25
Google Calendar MEDIUM 6.5
CVE-2019-10425

Jenkins Google Calendar Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ex…

Fix: after 0.4
Fix from $1,600 2019-09-25