Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pipeline\ HIGH 8.8
CVE-2018-1000866

A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxT…

Fix: after 2.59
Fix from $1,950 2018-12-10
Jenkins HIGH 8.2
CVE-2018-1000863EPSS 7%

A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to…

Fix: after 2.153
Fix from $1,950 2018-12-10
Jenkins MEDIUM 6.5
CVE-2018-1000864

A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Rea…

Fix: after 2.153
Fix from $1,600 2018-12-10
Jenkins MEDIUM 6.5
CVE-2018-1999047

A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel …

Fix: after 2.137
Fix from $1,600 2018-08-23
Jenkins HIGH 7.5
CVE-2018-1999043

A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuth…

Fix: after 2.137
Fix from $1,950 2018-08-23
Jenkins MEDIUM 6.5
CVE-2018-1999044

A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in CronTab.java that allows attackers with Overall/Read pe…

Fix: after 2.137
Fix from $1,600 2018-08-23
Jenkins MEDIUM 5.4
CVE-2018-1999045

A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2…

Fix: after 2.137
Fix from $1,600 2018-08-23
Jenkins MEDIUM 5.3
CVE-2018-1999042

A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name…

Fix: after 2.137
Fix from $1,600 2018-08-23
Email Extension MEDIUM 5.3
CVE-2017-2654

jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically…

Fix: 2.57.1+
Fix from $1,600 2018-08-06
Kubernetes HIGH 8.8
CVE-2018-1999040

An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attacke…

Fix: after 1.10.1
Fix from $1,950 2018-08-01
Tinfoil Security MEDIUM 5.5
CVE-2018-1999041

An exposure of sensitive information vulnerability exists in Jenkins Tinfoil Security Plugin 1.6.1 and earlier in TinfoilScanRecorder.java that allow…

Fix: after 1.6.1
Fix from $1,600 2018-08-01
Accurev HIGH 8.8
CVE-2018-1999028

An exposure of sensitive information vulnerability exists in Jenkins Accurev Plugin 0.7.16 and earlier in AccurevSCM.java that allows attackers to ca…

Fix: after 0.7.16
Fix from $1,950 2018-08-01
Saltstack HIGH 7.5
CVE-2018-1999027

An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that…

Fix: after 3.1.6
Fix from $1,950 2018-08-01
Tracetronic Ecu Test HIGH 7.4
CVE-2018-1999025

A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows a…

Fix: after 2.3
Fix from $1,950 2018-08-01
Inedo Proget HIGH 7.4
CVE-2018-1999034

A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.jav…

Fix: after 0.8
Fix from $1,950 2018-08-01
Inedo Buildmaster HIGH 7.4
CVE-2018-1999035

A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java…

Fix: after 1.3
Fix from $1,950 2018-08-01
Tracetronic Ecu Test MEDIUM 6.5
CVE-2018-1999026

A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers …

Fix: after 2.3
Fix from $1,600 2018-08-01
Meliora Testlab MEDIUM 6.5
CVE-2018-1999031

An exposure of sensitive information vulnerability exists in Jenkins meliora-testlab Plugin 1.14 and earlier in TestlabNotifier.java that allows atta…

Fix: after 1.14
Fix from $1,600 2018-08-01
Ssh Agent MEDIUM 6.5
CVE-2018-1999036

An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the…

Fix: after 1.15
Fix from $1,600 2018-08-01
Shelve Project MEDIUM 5.4
CVE-2018-1999029

A cross-site scripting vulnerability exists in Jenkins Shelve Project Plugin 1.5 and earlier in ShelveProjectAction/index.jelly, ShelvedProjectsActio…

Fix: after 1.5
Fix from $1,600 2018-08-01
Maven Artifact Choicelistprovider \(nexus\) MEDIUM 5.4
CVE-2018-1999030

An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and earlier in Artifactor…

Fix: after 1.3.1
Fix from $1,600 2018-08-01
Distributed Fork HIGH 8.8
CVE-2017-2652

It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the d…

Fix: after 1.5.0
Fix from $1,950 2018-07-27
Pipeline Classpath Step HIGH 8.5
CVE-2017-2650

It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access…

Mitigation only
Fix from $1,950 2018-07-27
Active Directory HIGH 8.1
CVE-2017-2649

It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server,…

Fix: after 2.2
Fix from $1,950 2018-07-27
Ssh Slaves MEDIUM 5.6
CVE-2017-2648

It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.

Fix: 1.15+
Fix from $1,600 2018-07-27
Jenkins HIGH 8.8
CVE-2018-1999001EPSS 18%

A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attacker…

Fix: after 2.132
Fix from $1,950 2018-07-23
Jenkins HIGH 7.5
CVE-2018-1999002EPSS 87%

A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapl…

Fix: after 2.132
Fix from $1,950 2018-07-23
Jenkins MEDIUM 5.4
CVE-2018-1999005

A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/contro…

Fix: after 2.132
Fix from $1,600 2018-07-23
Jenkins MEDIUM 5.4
CVE-2018-1999007

A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stap…

Fix: after 2.132
Fix from $1,600 2018-07-23
Aws Codepipeline HIGH 7.8
CVE-2018-1000401

Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipe…

Fix: after 0.36
Fix from $1,950 2018-07-09