Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jenkins HIGH 8.8
CVE-2017-2608EPSS 6%

Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserialization of various types in javax.i…

Fix: 2.32.2+
Fix from $1,950 2018-05-15
Jenkins MEDIUM 5.4
CVE-2017-2612

In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds…

Fix: 2.32.2 / 2.44+
Fix from $1,600 2018-05-15
Jenkins MEDIUM 5.4
CVE-2017-2601

Jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in parameter names and descriptions (SECURITY-353). Users with…

Fix: 2.32.2 / 2.44+
Fix from $1,600 2018-05-10
Html Publisher MEDIUM 6.5
CVE-2018-1000175

A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to confi…

Fix: after 1.15
Fix from $1,600 2018-05-08
Email Extension MEDIUM 6.5
CVE-2018-1000176

An exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/email…

Fix: after 2.61
Fix from $1,600 2018-05-08
Google Login MEDIUM 6.1
CVE-2018-1000174

An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirec…

Fix: after 1.3
Fix from $1,600 2018-05-08
Google Login MEDIUM 5.9
CVE-2018-1000173

A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized atta…

Fix: after 1.3
Fix from $1,600 2018-05-08
S3 Publisher MEDIUM 5.4
CVE-2018-1000177

A cross-site scripting vulnerability exists in Jenkins S3 Plugin 0.10.12 and older in src/main/resources/hudson/plugins/s3/S3ArtifactsProjectAction/j…

Fix: after 0.10.12
Fix from $1,600 2018-05-08
Jenkins MEDIUM 5.4
CVE-2018-1000170

A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that al…

Fix: after 2.107.1
Fix from $1,600 2018-04-16
Jenkins MEDIUM 5.3
CVE-2018-1000169

An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler…

Fix: after 2.107.1
Fix from $1,600 2018-04-16
Jenkins MEDIUM 5.4
CVE-2017-2599

Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.…

Fix: 2.32.2 / 2.44+
Fix from $1,600 2018-04-11
Liquibase Runner HIGH 8.8
CVE-2018-1000146

An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to config…

Fix: after 1.3.0
Fix from $1,950 2018-04-05
Vsphere HIGH 8.8
CVE-2018-1000153

A cross-site request forgery vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTempl…

Fix: after 2.16
Fix from $1,950 2018-04-05
Github Pull Request Builder HIGH 7.8
CVE-2018-1000142

An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java t…

Fix: after 1.39.0
Fix from $1,950 2018-04-05
Github Pull Request Builder MEDIUM 6.7
CVE-2018-1000143

An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java t…

Fix: after 1.39.0
Fix from $1,600 2018-04-05
Perforce MEDIUM 6.5
CVE-2018-1000145

An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that …

Fix: after 1.3.36
Fix from $1,600 2018-04-05
Copy To Slave MEDIUM 6.5
CVE-2018-1000148

An exposure of sensitive information vulnerability exists in Jenkins Copy To Slave Plugin version 1.4.4 and older in CopyToSlaveBuildWrapper.java tha…

Fix: after 1.4.4
Fix from $1,600 2018-04-05
Vsphere MEDIUM 6.3
CVE-2018-1000152

An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate…

Fix: after 2.16
Fix from $1,600 2018-04-05
Cucumber Living Documentation MEDIUM 6.1
CVE-2018-1000144

A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in CukedoctorBaseAction#doDynamic that d…

Fix: after 1.0.12
Fix from $1,600 2018-04-05
Ansible MEDIUM 5.6
CVE-2018-1000149

A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, …

Fix: after 0.8
Fix from $1,600 2018-04-05
Vsphere MEDIUM 5.6
CVE-2018-1000151

A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by def…

Fix: after 2.16
Fix from $1,600 2018-04-05
Mailer HIGH 8.0
CVE-2018-8718EPSS 7%

Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized ma…

Fix: after 1.20
Fix from $1,950 2018-03-27
Coverity HIGH 7.8
CVE-2018-1000104

A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with…

Fix: after 1.10.0
Fix from $1,950 2018-03-13
Job And Node Ownership MEDIUM 6.5
CVE-2018-1000107

An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobP…

Fix: after 0.11.0
Fix from $1,600 2018-03-13
Cppncss MEDIUM 6.1
CVE-2018-1000108

A cross-site scripting vulnerability exists in Jenkins CppNCSS Plugin 1.1 and earlier in AbstractProjectAction/index.jelly that allow an attacker to …

Fix: after 1.1
Fix from $1,600 2018-03-13
Gerrit Trigger MEDIUM 5.4
CVE-2018-1000106

An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and P…

Fix: after 2.27.4
Fix from $1,600 2018-03-13
Testlink MEDIUM 5.4
CVE-2018-1000113

A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and earlier in TestLinkBuildAction/summary.jelly and others that allow an…

Fix: after 3.12
Fix from $1,600 2018-03-13
Git MEDIUM 5.3
CVE-2018-1000110

An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network…

Fix: after 3.7.0
Fix from $1,600 2018-03-13
Subversion MEDIUM 5.3
CVE-2018-1000111

An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionReposit…

Fix: after 2.10.2
Fix from $1,600 2018-03-13
Mercurial MEDIUM 5.3
CVE-2018-1000112

An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker wi…

Fix: after 2.2
Fix from $1,600 2018-03-13