Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Octopusdeploy HIGH 8.8
CVE-2019-1003071

Jenkins OctopusDeploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users …

Mitigation only
Fix from $1,950 2019-04-04
Wildfly Deployer HIGH 8.8
CVE-2019-1003072

Jenkins WildFly Deployer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with E…

Mitigation only
Fix from $1,950 2019-04-04
Vs Team Services Continuous Deployment HIGH 8.8
CVE-2019-1003073

Jenkins VS Team Services Continuous Deployment Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be …

Mitigation only
Fix from $1,950 2019-04-04
Hyper.sh Commons HIGH 8.8
CVE-2019-1003074

Jenkins Hyper.sh Commons Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by use…

Mitigation only
Fix from $1,950 2019-04-04
Audit To Database HIGH 8.8
CVE-2019-1003075

Jenkins Audit to Database Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by us…

Mitigation only
Fix from $1,950 2019-04-04
Audit To Database MEDIUM 6.5
CVE-2019-1003076

A cross-site request forgery vulnerability in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form valida…

Mitigation only
Fix from $1,600 2019-04-04
Audit To Database MEDIUM 6.5
CVE-2019-1003077

A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allo…

Mitigation only
Fix from $1,600 2019-04-04
Vmware Lab Manager Slaves MEDIUM 6.5
CVE-2019-1003078

A cross-site request forgery vulnerability in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validat…

Mitigation only
Fix from $1,600 2019-04-04
Vmware Lab Manager Slaves MEDIUM 6.5
CVE-2019-1003079

A missing permission check in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validation method allow…

Fix: after 0.2.8
Fix from $1,600 2019-04-04
Openshift Deployer MEDIUM 6.5
CVE-2019-1003080

A cross-site request forgery vulnerability in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin for…

Fix: after 1.2.0
Fix from $1,600 2019-04-04
Openshift Deployer MEDIUM 6.5
CVE-2019-1003081

A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation met…

Fix: after 1.2.0
Fix from $1,600 2019-04-04
Gearman MEDIUM 6.5
CVE-2019-1003082

A cross-site request forgery vulnerability in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attack…

Mitigation only
Fix from $1,600 2019-04-04
Gearman MEDIUM 6.5
CVE-2019-1003083

A missing permission check in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attackers with Overall…

Fix: after 0.2.0
Fix from $1,600 2019-04-04
Zephyr Enterprise Test Management MEDIUM 6.5
CVE-2019-1003084

A cross-site request forgery vulnerability in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation …

Mitigation only
Fix from $1,600 2019-04-04
Zephyr Enterprise Test Management MEDIUM 6.5
CVE-2019-1003085

A missing permission check in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation method allows at…

Fix: after 1.6
Fix from $1,600 2019-04-04
Chef Sinatra MEDIUM 6.5
CVE-2019-1003086

A cross-site request forgery vulnerability in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form valida…

Mitigation only
Fix from $1,600 2019-04-04
Chef Sinatra MEDIUM 6.5
CVE-2019-1003087

A missing permission check in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allo…

Fix: after 1.2
Fix from $1,600 2019-04-04
Fabric Beta Publisher MEDIUM 6.5
CVE-2019-1003088

Jenkins Fabric Beta Publisher Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users w…

Fix: after 2.1
Fix from $1,600 2019-04-04
Upload To Pgyer MEDIUM 6.5
CVE-2019-1003089

Jenkins Upload to pgyer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ex…

Fix: after 1.31
Fix from $1,600 2019-04-04
Soasta Cloudtest MEDIUM 6.5
CVE-2019-1003090

A cross-site request forgery vulnerability in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method…

Mitigation only
Fix from $1,600 2019-04-04
Soasta Cloudtest MEDIUM 6.5
CVE-2019-1003091

A missing permission check in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method allows attacker…

Fix: after 2.25
Fix from $1,600 2019-04-04
Nomad MEDIUM 6.5
CVE-2019-1003092

A cross-site request forgery vulnerability in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows at…

Mitigation only
Fix from $1,600 2019-04-04
Nomad MEDIUM 6.5
CVE-2019-1003093

A missing permission check in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows attackers with Ove…

Fix: after 0.4
Fix from $1,600 2019-04-04
Irc HIGH 8.8
CVE-2019-1003051

Jenkins IRC Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with acces…

Mitigation only
Fix from $1,950 2019-04-04
Aws Elastic Beanstalk Publisher HIGH 8.8
CVE-2019-1003052

Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can b…

Mitigation only
Fix from $1,950 2019-04-04
Hockeyapp HIGH 8.8
CVE-2019-1003053

Jenkins HockeyApp Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended…

Mitigation only
Fix from $1,950 2019-04-04
Jira Issue Updater HIGH 8.8
CVE-2019-1003054

Jenkins Jira Issue Updater Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with…

Mitigation only
Fix from $1,950 2019-04-04
Ftp Publisher HIGH 8.8
CVE-2019-1003055

Jenkins FTP publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users …

Mitigation only
Fix from $1,950 2019-04-04
Websphere Deployer HIGH 8.8
CVE-2019-1003056

Jenkins WebSphere Deployer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with…

Mitigation only
Fix from $1,950 2019-04-04
Bitbucket Approve HIGH 8.8
CVE-2019-1003057

Jenkins Bitbucket Approve Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by us…

Mitigation only
Fix from $1,950 2019-04-04