Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

File System Scm MEDIUM 6.5
CVE-2019-10375

An arbitrary file read vulnerability in Jenkins File System SCM Plugin 2.1 and earlier allows attackers able to configure jobs in Jenkins to obtain t…

Fix: after 2.1
Fix from $1,600 2019-08-07
Gitlab Oauth MEDIUM 6.1
CVE-2019-10372

An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users…

Fix: after 1.4
Fix from $1,600 2019-08-07
Wall Display MEDIUM 6.1
CVE-2019-10376

A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inject arbitrary HTML and JavaSc…

Fix: after 0.6.34
Fix from $1,600 2019-08-07
Configuration As Code MEDIUM 5.5
CVE-2019-10367

Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expec…

Fix: after 1.26
Fix from $1,600 2019-08-07
Build Pipeline MEDIUM 5.4
CVE-2019-10373

A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to edit the build pipeline descr…

Fix: after 1.5.8
Fix from $1,600 2019-08-07
Pegdown Formatter MEDIUM 5.4
CVE-2019-10374

A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to edit descriptions and other …

Fix: after 1.3
Fix from $1,600 2019-08-07
Skytap Cloud Ci MEDIUM 6.5
CVE-2019-10366

Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be view…

Fix: after 2.06
Fix from $1,600 2019-07-31
Script Security HIGH 8.8
CVE-2019-10355

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute …

Fix: after 1.61
Fix from $1,950 2019-07-31
Script Security HIGH 8.8
CVE-2019-10356

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method pointer expressions allowed attac…

Fix: after 1.61
Fix from $1,950 2019-07-31
Maven MEDIUM 6.5
CVE-2019-10358

Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing sensitive build variables…

Fix: after 3.3
Fix from $1,600 2019-07-31
M2release MEDIUM 6.3
CVE-2019-10359

A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doSubmit method allowed attacker…

Fix: after 0.14.0
Fix from $1,600 2019-07-31
Configuration As Code MEDIUM 5.5
CVE-2019-10345

Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.

Fix: 1.20+
Fix from $1,600 2019-07-31
M2release MEDIUM 5.5
CVE-2019-10361

Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access …

Fix: after 0.14.0
Fix from $1,600 2019-07-31
Ec2 MEDIUM 5.5
CVE-2019-10364

Jenkins Amazon EC2 Plugin 1.43 and earlier wrote the beginning of private keys to the Jenkins system log.

Fix: after 1.43
Fix from $1,600 2019-07-31
M2 Release MEDIUM 5.4
CVE-2019-10360

A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScr…

Fix: after 0.14.0
Fix from $1,600 2019-07-31
Configuration As Code MEDIUM 5.4
CVE-2019-10362

Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when expo…

Fix: after 1.24
Fix from $1,600 2019-07-31
Credentials Binding MEDIUM 6.5
CVE-2019-1010241

Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated user…

No fix yet
Fix from $1,600 2019-07-19
Jenkins HIGH 7.5
CVE-2019-10353

CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF prote…

Fix: after 2.185
Fix from $1,950 2019-07-17
Jenkins MEDIUM 6.5
CVE-2019-10352EPSS 10%

A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allow…

Fix: after 2.185
Fix from $1,600 2019-07-17
Port Allocator HIGH 8.8
CVE-2019-10350

Jenkins Port Allocator Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ext…

Fix: after 1.8
Fix from $1,950 2019-07-11
Caliper Ci HIGH 8.8
CVE-2019-10351

Jenkins Caliper CI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extende…

Fix: after 2.3
Fix from $1,950 2019-07-11
Docker HIGH 8.8
CVE-2019-10340

A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with…

Fix: after 1.1.6
Fix from $1,950 2019-07-11
Mashup Portlets HIGH 8.8
CVE-2019-10347

Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users with access to the master file …

Fix: after 1.0.9
Fix from $1,950 2019-07-11
Gogs HIGH 8.8
CVE-2019-10348

Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read…

Fix: after 1.0.14
Fix from $1,950 2019-07-11
Docker MEDIUM 6.5
CVE-2019-10341

A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with Overall/Read ac…

Fix: after 1.1.6
Fix from $1,600 2019-07-11
Embeddable Build Status MEDIUM 6.1
CVE-2019-10346

A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML an…

Fix: after 2.0.1
Fix from $1,600 2019-07-11
Dependency Graph Viewer MEDIUM 5.4
CVE-2019-10349

A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Je…

Fix: after 0.13
Fix from $1,600 2019-07-11
Jx Resources HIGH 8.8
CVE-2019-10338

A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed at…

Fix: after 1.0.36
Fix from $1,950 2019-06-11
Jx Resources HIGH 8.8
CVE-2019-10339

A missing permission check in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed users with Overall…

Fix: after 1.0.36
Fix from $1,950 2019-06-11
Token Macro HIGH 7.5
CVE-2019-10337

An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the inp…

Fix: after 2.7
Fix from $1,950 2019-06-11