Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Aws Codedeploy HIGH 7.8
CVE-2018-1000403

Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeploy…

Fix: after 1.19
Fix from $1,950 2018-07-09
Aws Codebuild HIGH 7.8
CVE-2018-1000404

Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFacto…

Fix: after 0.26
Fix from $1,950 2018-07-09
GitHub HIGH 8.8
CVE-2018-1000600EPSS 91%

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allow…

Fix: after 1.29.1
Fix from $1,950 2018-06-26
Openstack Cloud HIGH 8.8
CVE-2018-1000603

A exposure of sensitive information vulnerability exists in Jenkins Openstack Cloud Plugin 2.35 and earlier in BootSource.java, InstancesToRun.java, …

Fix: after 2.35
Fix from $1,950 2018-06-26
Configuration As Code HIGH 8.8
CVE-2018-1000610

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java,…

Mitigation only
Fix from $1,950 2018-06-26
Collabnet HIGH 7.4
CVE-2018-1000605

A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidat…

Fix: after 2.0.4
Fix from $1,950 2018-06-26
Z\/os Connector HIGH 7.2
CVE-2018-1000608

A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker…

Fix: after 1.2.6.1
Fix from $1,950 2018-06-26
Ssh Credentials MEDIUM 6.5
CVE-2018-1000601

A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers wi…

Fix: after 1.13
Fix from $1,600 2018-06-26
Urltrigger MEDIUM 6.5
CVE-2018-1000606

A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overal…

Fix: after 0.41
Fix from $1,600 2018-06-26
Fortify Cloudscan MEDIUM 6.5
CVE-2018-1000607

A arbitrary file write vulnerability exists in Jenkins Fortify CloudScan Plugin 1.5.1 and earlier in ArchiveUtil.java that allows attackers able to c…

Fix: after 1.5.1
Fix from $1,600 2018-06-26
Configuration As Code MEDIUM 6.5
CVE-2018-1000609

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java th…

Mitigation only
Fix from $1,600 2018-06-26
Saml MEDIUM 5.9
CVE-2018-1000602

A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impe…

Fix: after 1.0.6
Fix from $1,600 2018-06-26
Badge MEDIUM 5.4
CVE-2018-1000604

A persisted cross-site scripting vulnerability exists in Jenkins Badge Plugin 1.4 and earlier in BadgeSummaryAction.java, HtmlBadgeAction.java that a…

Fix: after 1.4
Fix from $1,600 2018-06-26
Jenkins HIGH 8.1
CVE-2018-1000194

A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicio…

Fix: after 2.120
Fix from $1,950 2018-06-05
Black Duck Hub HIGH 8.1
CVE-2018-1000197

An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users wit…

Fix: after 3.0.3
Fix from $1,950 2018-06-05
Gitlab Hook MEDIUM 6.5
CVE-2018-1000196

A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifier.rb, views/gitlab_notifier/g…

Fix: after 1.4.2
Fix from $1,600 2018-06-05
Black Duck Hub MEDIUM 6.5
CVE-2018-1000198

A XML external entity processing vulnerability exists in Jenkins Black Duck Hub Plugin 3.1.0 and older in PostBuildScanDescriptor.java that allows at…

Fix: after 3.1.0
Fix from $1,600 2018-06-05
Groovy Postbuild MEDIUM 5.4
CVE-2018-1000202

A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers…

Fix: after 2.3.1
Fix from $1,600 2018-06-05
Absint Astree HIGH 8.8
CVE-2018-1000189

A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allows attackers with Overall/Rea…

Fix: after 1.0.5
Fix from $1,950 2018-06-05
GitHub MEDIUM 6.5
CVE-2018-1000183

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers w…

Fix: after 1.29.0
Fix from $1,600 2018-06-05
Github Pull Request Builder MEDIUM 6.5
CVE-2018-1000186

A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that …

Fix: after 1.41.0
Fix from $1,600 2018-06-05
Kubernetes MEDIUM 6.5
CVE-2018-1000187

A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in …

Fix: after 1.7.0
Fix from $1,600 2018-06-05
Black Duck Hub MEDIUM 6.5
CVE-2018-1000190

A exposure of sensitive information vulnerability exists in Jenkins Black Duck Hub Plugin 4.0.0 and older in PostBuildScanDescriptor.java that allows…

Fix: after 4.0.0
Fix from $1,600 2018-06-05
Synopsys Detect MEDIUM 6.5
CVE-2018-1000191

A exposure of sensitive information vulnerability exists in Jenkins Black Duck Detect Plugin 1.4.0 and older in DetectPostBuildStepDescriptor.java th…

Fix: after 1.4.0
Fix from $1,600 2018-06-05
Git MEDIUM 6.4
CVE-2018-1000182

A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.…

Fix: after 3.9.0
Fix from $1,600 2018-06-05
GitHub MEDIUM 5.4
CVE-2018-1000184

A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Ov…

Fix: after 1.29.0
Fix from $1,600 2018-06-05
Cas MEDIUM 5.4
CVE-2018-1000188

A server-side request forgery vulnerability exists in Jenkins CAS Plugin 1.4.1 and older in CasSecurityRealm.java that allows attackers with Overall/…

Fix: after 1.4.1
Fix from $1,600 2018-06-05
Jenkins MEDIUM 5.4
CVE-2017-2607

jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting vulnerability in console notes (SECURITY-382). Jenkins allows …

Fix: 2.32.2 / 2.44+
Fix from $1,600 2018-05-21
Jenkins MEDIUM 5.4
CVE-2017-2613

jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record was only retained until restar…

Fix: 2.32.2 / 2.44+
Fix from $1,600 2018-05-15
Jenkins MEDIUM 5.4
CVE-2017-2610

jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in search suggestions due to improperly escaping users with le…

Fix: 2.32.2 / 2.44+
Fix from $1,600 2018-05-15