Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Electricflow MEDIUM 6.1
CVE-2019-10336

A reflected cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.6 and earlier allowed attackers able to control the output of the E…

Fix: after 1.1.6
Fix from $1,600 2019-06-11
Electricflow MEDIUM 6.5
CVE-2019-10334

Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM when MultipartUtility.ja…

Fix: after 1.1.5
Fix from $1,600 2019-06-11
Electricflow MEDIUM 5.4
CVE-2019-10335

A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to configure jobs in Jenkins or c…

Fix: after 1.1.6
Fix from $1,600 2019-06-11
Pipeline Remote Loader CRITICAL 9.9
CVE-2019-10328

Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary meth…

Fix: after 1.4
Fix from $2,300 2019-05-31
Pipeline Maven Integration HIGH 8.1
CVE-2019-10327

An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a tempo…

Fix: after 1.7.0
Fix from $1,950 2019-05-31
Warnings Next Generation MEDIUM 5.4
CVE-2019-10325

A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitra…

Fix: after 5.0.0
Fix from $1,600 2019-05-31
Self Organizing Swarm Modules CRITICAL 9.3
CVE-2019-10309

Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity p…

Mitigation only
Fix from $2,300 2019-04-30
Ansible Tower HIGH 8.8
CVE-2019-10310

A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doT…

Fix: after 0.9.1
Fix from $1,950 2019-04-30
Ansible Tower HIGH 8.8
CVE-2019-10311

A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnecti…

Fix: after 0.9.1
Fix from $1,950 2019-04-30
Twitter HIGH 8.8
CVE-2019-10313

Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with a…

Fix: after 0.7
Fix from $1,950 2019-04-30
Github Authentication HIGH 8.8
CVE-2019-10315

Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent CSRF.

Fix: after 0.31
Fix from $1,950 2019-04-30
Aqua Microscanner HIGH 8.8
CVE-2019-10316

Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they c…

Fix: after 1.0.5
Fix from $1,950 2019-04-30
Azure Ad HIGH 8.8
CVE-2019-10318

Jenkins Azure AD Plugin 0.3.3 and earlier stored the client secret unencrypted in the global config.xml configuration file on the Jenkins master wher…

Fix: after 0.3.3
Fix from $1,950 2019-04-30
Static Analysis Utilities MEDIUM 6.5
CVE-2019-10307

A cross-site request forgery vulnerability in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave f…

Fix: after 1.95
Fix from $1,600 2019-04-30
Static Analysis Utilities MEDIUM 6.5
CVE-2019-10308

A missing permission check in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave form handler meth…

Fix: after 1.95
Fix from $1,600 2019-04-30
Koji MEDIUM 5.9
CVE-2019-10314

Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

Fix: after 0.3
Fix from $1,600 2019-04-30
Sitemonitor MEDIUM 5.9
CVE-2019-10317

Jenkins SiteMonitor Plugin 0.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.

Fix: after 0.5
Fix from $1,600 2019-04-30
Ontrack CRITICAL 9.9
CVE-2019-10306

A sandbox bypass vulnerability in Jenkins ontrack Plugin 3.4 and earlier allowed attackers with control over ontrack DSL definitions to execute arbit…

Fix: after 3.4
Fix from $2,300 2019-04-18
GitLab HIGH 8.8
CVE-2019-10301

A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed …

Fix: after 1.5.11
Fix from $1,950 2019-04-18
Jira Ext HIGH 8.8
CVE-2019-10302

Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be vie…

Fix: after 0.8
Fix from $1,950 2019-04-18
Azure Publishersettings Credentials HIGH 8.8
CVE-2019-10303

Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master w…

Fix: after 1.2
Fix from $1,950 2019-04-18
GitLab HIGH 8.0
CVE-2019-10300

A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation…

Fix: after 1.5.11
Fix from $1,950 2019-04-18
Xebialabs Xl Deploy MEDIUM 6.5
CVE-2019-10304

A cross-site request forgery vulnerability in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method …

Fix: after 7.5.3
Fix from $1,600 2019-04-18
Xebialabs Xl Deploy MEDIUM 6.5
CVE-2019-10305

A missing permission check in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method allows attackers…

Fix: after 7.5.3
Fix from $1,600 2019-04-18
Jenkins HIGH 8.1
CVE-2019-1003049

Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins …

Fix: after 2.171
Fix from $1,950 2019-04-10
Jenkins MEDIUM 5.4
CVE-2019-1003050

The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlie…

Fix: after 2.171
Fix from $1,600 2019-04-10
Kmap HIGH 8.8
CVE-2019-10294

Jenkins Kmap Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read…

Mitigation only
Fix from $1,950 2019-04-04
Crittercism Dsym HIGH 8.8
CVE-2019-10295

Jenkins crittercism-dsym Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with E…

Mitigation only
Fix from $1,950 2019-04-04
Serena Sra Deploy HIGH 8.8
CVE-2019-10296

Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by us…

Mitigation only
Fix from $1,950 2019-04-04
Sametime HIGH 8.8
CVE-2019-10297

Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with …

Mitigation only
Fix from $1,950 2019-04-04