Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Official Owasp Zap HIGH 8.8
CVE-2019-1003060

Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by u…

Mitigation only
Fix from $1,950 2019-04-04
Jenkins Cloudformation Plugin HIGH 8.8
CVE-2019-1003061

Jenkins jenkins-cloudformation-plugin Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by…

Mitigation only
Fix from $1,950 2019-04-04
Aws Cloudwatch Logs Publisher HIGH 8.8
CVE-2019-1003062

Jenkins AWS CloudWatch Logs Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be …

Mitigation only
Fix from $1,950 2019-04-04
Amazon Sns Build Notifier HIGH 8.8
CVE-2019-1003063

Jenkins Amazon SNS Build Notifier Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be view…

Mitigation only
Fix from $1,950 2019-04-04
Aws Device Farm HIGH 8.8
CVE-2019-1003064

Jenkins aws-device-farm Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by user…

Mitigation only
Fix from $1,950 2019-04-04
Cloudshare Docker Machine HIGH 8.8
CVE-2019-1003065

Jenkins CloudShare Docker-Machine Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be view…

Mitigation only
Fix from $1,950 2019-04-04
Ftp Publisher MEDIUM 6.5
CVE-2019-1003058

A cross-site request forgery vulnerability in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers to…

Mitigation only
Fix from $1,600 2019-04-04
Ftp Publisher MEDIUM 6.5
CVE-2019-1003059

A missing permission check in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers with Overall/Read …

Mitigation only
Fix from $1,600 2019-04-04
Script Security CRITICAL 9.8
CVE-2019-1003040

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scri…

Fix: after 1.55
Fix from $2,300 2019-03-28
Pipeline\ CRITICAL 9.8
CVE-2019-1003041

A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scr…

Fix: after 2.64
Fix from $2,300 2019-03-28
Prqa HIGH 7.8
CVE-2019-1003048

A vulnerability in Jenkins PRQA Plugin 3.1.0 and earlier allows attackers with local file system access to the Jenkins home directory to obtain the u…

Fix: after 3.1.0
Fix from $1,950 2019-03-28
Slack Notification HIGH 7.5
CVE-2019-1003043

A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read permission to connect to an attac…

Fix: after 2.19
Fix from $1,950 2019-03-28
Slack Notification HIGH 7.1
CVE-2019-1003044

A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified…

Fix: after 2.19
Fix from $1,950 2019-03-28
Fortify On Demand Uploader MEDIUM 6.5
CVE-2019-1003046

A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers to initiate a connection …

Fix: after 3.0.10
Fix from $1,600 2019-03-28
Fortify On Demand Uploader MEDIUM 6.5
CVE-2019-1003047

A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate …

Fix: after 3.0.10
Fix from $1,600 2019-03-28
Lockable Resources MEDIUM 5.4
CVE-2019-1003042

A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to control resource names to inject a…

Fix: after 2.4
Fix from $1,600 2019-03-28
Script Security CRITICAL 9.9
CVE-2019-1003029 KEVEPSS 74%

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbo…

Fix: after 1.53
Fix from $2,300 2019-03-08
Pipeline\ CRITICAL 9.9
CVE-2019-1003030 KEVEPSS 97%

A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cp…

Fix: after 2.63
Fix from $2,300 2019-03-08
Matrix Project CRITICAL 9.9
CVE-2019-1003031

A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java tha…

Fix: after 1.13
Fix from $2,300 2019-03-08
Email Extension CRITICAL 9.9
CVE-2019-1003032

A sandbox bypass vulnerability exists in Jenkins Email Extension Plugin 2.64 and earlier in pom.xml, src/main/java/hudson/plugins/emailext/ExtendedEm…

Fix: after 2.64
Fix from $2,300 2019-03-08
Job Dsl CRITICAL 9.9
CVE-2019-1003034

A sandbox bypass vulnerability exists in Jenkins Job DSL Plugin 1.71 and earlier in job-dsl-core/src/main/groovy/javaposse/jobdsl/dsl/AbstractDslScri…

Fix: after 1.71
Fix from $2,300 2019-03-08
Groovy HIGH 8.8
CVE-2019-1003033

A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.1 and earlier in pom.xml, src/main/java/hudson/plugins/groovy/StringScriptSource.jav…

Fix: after 2.1
Fix from $1,950 2019-03-08
Appdynamics HIGH 8.8
CVE-2019-1003039

An insufficiently protected credentials vulnerability exists in JenkinsAppDynamics Dashboard Plugin 1.0.14 and earlier in src/main/java/nl/codecentri…

Fix: after 1.0.14
Fix from $1,950 2019-03-08
Repository Connector HIGH 7.8
CVE-2019-1003038

An insufficiently protected credentials vulnerability exists in Jenkins Repository Connector Plugin 1.2.4 and earlier in src/main/java/org/jvnet/huds…

Fix: after 1.2.4
Fix from $1,950 2019-03-08
Azure Vm Agents MEDIUM 6.5
CVE-2019-1003037

An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVM…

Fix: after 0.8.0
Fix from $1,600 2019-03-08
Script Security HIGH 8.8
CVE-2019-1003024

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectASTTransformsCustomizer.java that allows attackers …

Fix: after 1.52
Fix from $1,950 2019-02-20
Cloud Foundry HIGH 8.8
CVE-2019-1003025

A exposure of sensitive information vulnerability exists in Jenkins Cloud Foundry Plugin 2.3.1 and earlier in AbstractCloudFoundryPushDescriptor.java…

Fix: after 2.3.1
Fix from $1,950 2019-02-20
Monitoring MEDIUM 6.5
CVE-2019-1003022

A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads run…

Fix: after 1.74.0
Fix from $1,600 2019-02-06
Warnings Next Generation MEDIUM 6.1
CVE-2019-1003023

A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/java/io/jenkins/plugins/analysis…

Fix: after 1.0.1
Fix from $1,600 2019-02-06
Job Import CRITICAL 9.1
CVE-2019-1003015

An XML external entity processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport…

Fix: after 2.1
Fix from $2,300 2019-02-06