Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jenkins MEDIUM 6.5
CVE-2018-6356

Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing…

Fix: 2.89.4 / 2.107+
Fix from $1,600 2018-02-20
Jenkins MEDIUM 5.3
CVE-2018-1000067

An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jen…

Fix: after 2.106
Fix from $1,600 2018-02-16
Jenkins MEDIUM 5.3
CVE-2018-1000068

An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to acces…

Fix: after 2.106
Fix from $1,600 2018-02-16
Pipeline Supporting Apis HIGH 8.8
CVE-2018-1000058

Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to J…

Fix: after 2.17
Fix from $1,950 2018-02-09
Junit HIGH 8.3
CVE-2018-1000056

Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user p…

Fix: after 1.23
Fix from $1,950 2018-02-09
Ccm HIGH 8.3
CVE-2018-1000054

Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user perm…

Fix: after 3.1
Fix from $1,950 2018-02-09
Android Lint HIGH 8.3
CVE-2018-1000055

Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with …

Fix: after 2.5
Fix from $1,950 2018-02-09
Jenkins CRITICAL 9.8
CVE-2017-1000353 KEVEPSS 100%

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated re…

Fix: after 2.56
Fix from $2,300 2018-01-29
Jenkins HIGH 8.8
CVE-2017-1000354

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to a login command which allowed impersonating any Jenkins user. T…

Fix: after 2.56
Fix from $1,950 2018-01-29
Jenkins HIGH 8.8
CVE-2017-1000356EPSS 7%

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an issue in the Jenkins user database authentication realm: cre…

Fix: after 2.56
Fix from $1,950 2018-01-29
Jenkins MEDIUM 6.5
CVE-2017-1000355

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void.

Fix: after 2.56
Fix from $1,600 2018-01-29
Speaks\! HIGH 8.8
CVE-2017-1000403

Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effecti…

Fix: after 0.1.1
Fix from $1,950 2018-01-26
Delivery Pipeline MEDIUM 6.1
CVE-2017-1000404

The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resu…

Fix: after 1.0.7
Fix from $1,600 2018-01-26
Swarm MEDIUM 5.9
CVE-2017-1000402

Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly…

Fix: after 3.4
Fix from $1,600 2018-01-26
Jenkins HIGH 8.8
CVE-2017-1000393

Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could configure a launch method called 'L…

Fix: after 2.83
Fix from $1,950 2018-01-26
Build Publisher HIGH 7.8
CVE-2017-1000387

Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.Buil…

Fix: after 1.21
Fix from $1,950 2018-01-26
Jenkins HIGH 7.5
CVE-2017-1000394

Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CV…

Fix: after 2.83
Fix from $1,950 2018-01-26
Jenkins HIGH 7.3
CVE-2017-1000391

Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual user accounts, as well as user…

Fix: after 2.88
Fix from $1,950 2018-01-26
Global Build Stats MEDIUM 6.1
CVE-2017-1000389

Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These res…

Fix: after 1.4
Fix from $1,600 2018-01-26
Jenkins MEDIUM 5.9
CVE-2017-1000396

Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectl…

Fix: after 2.83
Fix from $1,600 2018-01-26
Maven MEDIUM 5.9
CVE-2017-1000397

Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verif…

Fix: after 2.17
Fix from $1,600 2018-01-26
Active Choices MEDIUM 5.4
CVE-2017-1000386

Jenkins Active Choices plugin version 1.5.3 and earlier allowed users with Job/Configure permission to provide arbitrary HTML to be shown on the 'Bui…

Fix: after 1.5.2
Fix from $1,600 2018-01-26
Script Security MEDIUM 6.5
CVE-2017-1000505

In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coerc…

Fix: after 1.36
Fix from $1,600 2018-01-25
Ec2 HIGH 8.8
CVE-2017-1000502

Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the m…

Fix: after 1.37
Fix from $1,950 2018-01-24
Jenkins HIGH 8.1
CVE-2017-1000503

A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of execution of commands during initial…

Fix: after 2.94
Fix from $1,950 2018-01-24
Jenkins HIGH 8.1
CVE-2017-1000504

A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initiali…

Fix: after 2.94
Fix from $1,950 2018-01-24
Pmd HIGH 8.8
CVE-2018-1000008

Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user per…

Fix: after 3.49
Fix from $1,950 2018-01-23
Checkstyle HIGH 8.8
CVE-2018-1000009

Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with u…

Fix: after 3.49
Fix from $1,950 2018-01-23
Dry HIGH 8.8
CVE-2018-1000010

Jenkins DRY Plugin 2.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user per…

Fix: after 2.49
Fix from $1,950 2018-01-23
Findbugs HIGH 8.8
CVE-2018-1000011

Jenkins FindBugs Plugin 4.71 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with use…

Fix: after 4.71
Fix from $1,950 2018-01-23