Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Koji HIGH 8.8
CVE-2019-10298

Jenkins Koji Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with acce…

Mitigation only
Fix from $1,950 2019-04-04
Cloudcoreo Deploytime HIGH 8.8
CVE-2019-10299

Jenkins CloudCoreo DeployTime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed b…

Mitigation only
Fix from $1,950 2019-04-04
Kmap MEDIUM 6.5
CVE-2019-10292

A cross-site request forgery vulnerability in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows attackers to in…

Mitigation only
Fix from $1,600 2019-04-04
Kmap MEDIUM 6.5
CVE-2019-10293

A missing permission check in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows attackers with Overall/Read per…

Mitigation only
Fix from $1,600 2019-04-04
Starteam HIGH 8.8
CVE-2019-10277

Jenkins StarTeam Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended …

Mitigation only
Fix from $1,950 2019-04-04
Assembla Auth HIGH 8.8
CVE-2019-10280

Jenkins Assembla Auth Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewe…

Mitigation only
Fix from $1,950 2019-04-04
Relution Enterprise Appstore Publisher HIGH 8.8
CVE-2019-10281

Jenkins Relution Enterprise Appstore Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where the…

Mitigation only
Fix from $1,950 2019-04-04
Klaros Testmanagement HIGH 8.8
CVE-2019-10282

Jenkins Klaros-Testmanagement Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users w…

Mitigation only
Fix from $1,950 2019-04-04
Mabl HIGH 8.8
CVE-2019-10283

Jenkins mabl Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read…

Mitigation only
Fix from $1,950 2019-04-04
Diawi Upload HIGH 8.8
CVE-2019-10284

Jenkins Diawi Upload Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Exten…

Mitigation only
Fix from $1,950 2019-04-04
Minio Storage HIGH 8.8
CVE-2019-10285

Jenkins Minio Storage Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users …

Mitigation only
Fix from $1,950 2019-04-04
Deployhub HIGH 8.8
CVE-2019-10286

Jenkins DeployHub Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended…

Mitigation only
Fix from $1,950 2019-04-04
Youtrack Plugin HIGH 8.8
CVE-2019-10287

Jenkins youtrack-plugin Plugin 0.7.1 and older stored credentials unencrypted in its global configuration file on the Jenkins master where they could…

Fix: after 0.7.1
Fix from $1,950 2019-04-04
Jabber Server HIGH 8.8
CVE-2019-10288

Jenkins Jabber Server Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users …

Mitigation only
Fix from $1,950 2019-04-04
Netsparker Cloud Scan HIGH 8.8
CVE-2019-10291

Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older stored credentials unencrypted in its global configuration file on the Jenkins master where they…

Fix: after 1.1.5
Fix from $1,950 2019-04-04
Open Stf MEDIUM 6.5
CVE-2019-1003094

Jenkins Open STF Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with …

Fix: after 1.0.9
Fix from $1,600 2019-04-04
Perfecto Mobile MEDIUM 6.5
CVE-2019-1003095

Jenkins Perfecto Mobile Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by user…

Fix: after 2.62.0.3
Fix from $1,600 2019-04-04
Testfairy MEDIUM 6.5
CVE-2019-1003096

Jenkins TestFairy Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended…

Fix: after 4.16
Fix from $1,600 2019-04-04
Crowd Integration MEDIUM 6.5
CVE-2019-1003097

Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be v…

Fix: after 1.2
Fix from $1,600 2019-04-04
Openid MEDIUM 6.5
CVE-2019-1003098

A cross-site request forgery vulnerability in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method al…

Mitigation only
Fix from $1,600 2019-04-04
Openid MEDIUM 6.5
CVE-2019-1003099

A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers w…

Fix: after 2.3
Fix from $1,600 2019-04-04
Jenkins Reviewbot MEDIUM 6.5
CVE-2019-10278

A cross-site request forgery vulnerability in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method a…

Mitigation only
Fix from $1,600 2019-04-04
Jenkins Reviewbot MEDIUM 6.5
CVE-2019-10279

A missing permission check in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers …

Mitigation only
Fix from $1,600 2019-04-04
Netsparker Cloud Scan MEDIUM 6.5
CVE-2019-10289

A cross-site request forgery vulnerability in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI …

Fix: after 1.1.5
Fix from $1,600 2019-04-04
Netsparker Cloud Scan MEDIUM 6.5
CVE-2019-10290

A missing permission check in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI form validation …

Fix: after 1.1.5
Fix from $1,600 2019-04-04
Bugzilla HIGH 8.8
CVE-2019-1003066

Jenkins Bugzilla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with …

Mitigation only
Fix from $1,950 2019-04-04
Trac Publisher HIGH 8.8
CVE-2019-1003067

Jenkins Trac Publisher Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ext…

Mitigation only
Fix from $1,950 2019-04-04
Vmware Vrealize Automation HIGH 8.8
CVE-2019-1003068

Jenkins VMware vRealize Automation Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by us…

Mitigation only
Fix from $1,950 2019-04-04
Aqua Security Scanner HIGH 8.8
CVE-2019-1003069

Jenkins Aqua Security Scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed b…

Mitigation only
Fix from $1,950 2019-04-04
Veracode Scanner HIGH 8.8
CVE-2019-1003070

Jenkins veracode-scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by use…

Mitigation only
Fix from $1,950 2019-04-04