Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vfabric Application Director MEDIUM 5.5
CVE-2019-10419

Jenkins vFabric Application Director Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be v…

Fix: after 1.3
Fix from $1,600 2019-09-25
Assembla MEDIUM 5.5
CVE-2019-10420

Jenkins Assembla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with …

Fix: after 1.4
Fix from $1,600 2019-09-25
Codescan MEDIUM 5.5
CVE-2019-10423

Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with …

Fix: after 0.11
Fix from $1,600 2019-09-25
Eloyente MEDIUM 5.5
CVE-2019-10424

Jenkins elOyente Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with …

Fix: after 1.3
Fix from $1,600 2019-09-25
Gem Publisher MEDIUM 5.5
CVE-2019-10426

Jenkins Gem Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users …

Fix: after 1.0
Fix from $1,600 2019-09-25
Log Parser MEDIUM 5.4
CVE-2019-10410

Jenkins Log Parser Plugin 2.0 and earlier did not escape an error message, resulting in a cross-site scripting vulnerability exploitable by users abl…

Fix: after 2.0
Fix from $1,600 2019-09-25
Project Inheritance MEDIUM 6.5
CVE-2019-10407

Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passed to a build without masking sensitive variables …

Fix: after 2.0.0
Fix from $1,600 2019-09-25
Jenkins MEDIUM 5.4
CVE-2019-10401

In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as HTML when expanded, resulting …

Fix: after 2.196
Fix from $1,600 2019-09-25
Jenkins MEDIUM 5.4
CVE-2019-10402

In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:combobox form control interpreted its item labels as HTML, resulting in a stored XSS vul…

Fix: after 2.196
Fix from $1,600 2019-09-25
Jenkins MEDIUM 5.4
CVE-2019-10403

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vuln…

Fix: after 2.196
Fix from $1,600 2019-09-25
Jenkins MEDIUM 5.4
CVE-2019-10404

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the reason why a queue items is blcoked in tooltips, resulting in a stored XSS vuln…

Fix: after 2.196
Fix from $1,600 2019-09-25
Jenkins MEDIUM 5.4
CVE-2019-10405EPSS 66%

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers expl…

Fix: after 2.196
Fix from $1,600 2019-09-25
Git Client HIGH 8.8
CVE-2019-10392EPSS 26%

Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote',…

Fix: after 2.8.4
Fix from $1,950 2019-09-12
Beaker Builder MEDIUM 5.5
CVE-2019-10398

Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could …

Fix: after 1.9
Fix from $1,600 2019-09-12
Build Environment MEDIUM 5.4
CVE-2019-10395

Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Je…

Fix: after 1.6
Fix from $1,600 2019-09-12
Dashboard View MEDIUM 5.4
CVE-2019-10396

Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vulnerability exploitable by us…

Fix: after 2.11
Fix from $1,600 2019-09-12
Splunk HIGH 8.8
CVE-2019-10390

A sandbox bypass vulnerability in Jenkins Splunk Plugin 1.7.4 and earlier allowed attackers with Overall/Read permission to provide a Groovy script t…

Fix: after 1.7.4
Fix from $1,950 2019-08-28
Ibm Application Security On Cloud MEDIUM 6.5
CVE-2019-10391

Jenkins IBM Application Security on Cloud Plugin 1.2.4 and earlier transmitted configured passwords in plain text as part of job configuration forms,…

Fix: after 1.2.4
Fix from $1,600 2019-08-28
Jenkins HIGH 8.8
CVE-2019-10384

Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens…

Fix: after 2.191
Fix from $1,950 2019-08-28
Simple Travis Pipeline Runner HIGH 8.8
CVE-2019-10380

Jenkins Simple Travis Pipeline Runner Plugin 1.0 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able…

Fix: after 1.0
Fix from $1,950 2019-08-07
Xl Testview HIGH 8.8
CVE-2019-10386

A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows use…

Fix: after 1.2.0
Fix from $1,950 2019-08-07
Codefresh Integration HIGH 7.5
CVE-2019-10381

Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

Fix: after 1.8
Fix from $1,950 2019-08-07
Vmware Lab Manager Slaves MEDIUM 6.5
CVE-2019-10382

Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

Fix: after 0.2.8
Fix from $1,600 2019-08-07
Eggplant MEDIUM 6.5
CVE-2019-10385

Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by user…

Fix: after 2.2
Fix from $1,600 2019-08-07
Xl Testview MEDIUM 6.5
CVE-2019-10387

A missing permission check in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/…

Fix: after 1.2.0
Fix from $1,600 2019-08-07
Testlink MEDIUM 5.3
CVE-2019-10378

Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be view…

Fix: after 3.16
Fix from $1,600 2019-08-07
Jclouds HIGH 8.8
CVE-2019-10368

A cross-site request forgery vulnerability in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JClouds…

Fix: after 2.14
Fix from $1,950 2019-08-07
Gitlab Oauth HIGH 7.5
CVE-2019-10371

A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to…

Fix: after 1.4
Fix from $1,950 2019-08-07
Jclouds MEDIUM 6.5
CVE-2019-10369

A missing permission check in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JCloudsCloud.Descriptor…

Fix: after 2.14
Fix from $1,600 2019-08-07
Mask Passwords MEDIUM 6.5
CVE-2019-10370

Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially…

Fix: after 2.12.0
Fix from $1,600 2019-08-07