Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Warnings HIGH 8.8
CVE-2018-1000012

Jenkins Warnings Plugin 4.64 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with use…

Fix: after 4.64
Fix from $1,950 2018-01-23
Release HIGH 8.8
CVE-2018-1000013

Jenkins Release Plugin 2.9 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vulnerability allowing attacker…

Fix: after 2.9
Fix from $1,950 2018-01-23
Translation Assistance HIGH 8.8
CVE-2018-1000014

Jenkins Translation Assistance Plugin 1.15 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vulnerability a…

Fix: after 1.15
Fix from $1,950 2018-01-23
Ssh CRITICAL 9.8
CVE-2017-1000245

The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH ke…

Fix: after 2.4
Fix from $2,300 2017-11-01
Favorite HIGH 8.8
CVE-2017-1000244

Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification

Fix: after 2.2.0
Fix from $1,950 2017-11-01
Script Security HIGH 8.8
CVE-2017-1000107

Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations,…

Mitigation only
Fix from $1,950 2017-10-05
Blue Ocean HIGH 8.5
CVE-2017-1000106

Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing …

Fix: after 1.1.5
Fix from $1,950 2017-10-05
Pipeline Input Step HIGH 7.5
CVE-2017-1000108

The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has bee…

Mitigation only
Fix from $1,950 2017-10-05
Config File Provider MEDIUM 6.5
CVE-2017-1000104

The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overal…

Fix: after 2.16.1
Fix from $1,600 2017-10-05
Owasp Dependency Check MEDIUM 6.1
CVE-2017-1000109

The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vuln…

Mitigation only
Fix from $1,600 2017-10-05
Deploy MEDIUM 5.5
CVE-2017-1000113

The Deploy to container Plugin stored passwords unencrypted as part of its configuration. This allowed users with Jenkins master local file system ac…

Fix: after 1.12
Fix from $1,600 2017-10-05
Static Analysis Utilities MEDIUM 5.4
CVE-2017-1000102

The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users a…

Fix: after 1.91
Fix from $1,600 2017-10-05
Dry MEDIUM 5.4
CVE-2017-1000103

The custom Details view of the Static Analysis Utilities based DRY Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Maliciou…

Fix: after 2.48
Fix from $1,600 2017-10-05
Blue Ocean MEDIUM 5.3
CVE-2017-1000105

The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing acc…

Fix: after 1.1.5
Fix from $1,600 2017-10-05
Role Based Authorization Strategy HIGH 8.8
CVE-2017-1000090

Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery…

Fix: after 2.5.0
Fix from $1,950 2017-10-05
Poll Scm HIGH 8.8
CVE-2017-1000093

Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed at…

Fix: after 1.3.1
Fix from $1,950 2017-10-05
Pipeline\ HIGH 8.8
CVE-2017-1000096

Arbitrary code execution due to incomplete sandbox protection: Constructors, instance variable initializers, and instance initializers in Pipeline sc…

Fix: after 2.36
Fix from $1,950 2017-10-05
Periodic Backup HIGH 8.0
CVE-2017-1000086

The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups,…

Mitigation only
Fix from $1,950 2017-10-05
Git HIGH 7.5
CVE-2017-1000092

Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at …

Mitigation only
Fix from $1,950 2017-10-05
Parameterized Trigger MEDIUM 6.5
CVE-2017-1000084

Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was run…

Mitigation only
Fix from $1,600 2017-10-05
Subversion MEDIUM 6.5
CVE-2017-1000085

Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality…

Fix: after 2.8
Fix from $1,600 2017-10-05
Docker Commons MEDIUM 6.5
CVE-2017-1000094

Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use to authentic…

Fix: after 1.9
Fix from $1,600 2017-10-05
Script Security MEDIUM 6.5
CVE-2017-1000095

The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, S…

Mitigation only
Fix from $1,600 2017-10-05
Github Branch Source MEDIUM 6.3
CVE-2017-1000091

GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to v…

Mitigation only
Fix from $1,600 2017-10-05
Sidebar Link MEDIUM 5.4
CVE-2017-1000088

The Sidebar Link plugin allows users able to configure jobs, views, and agents to add entries to the sidebar of these objects. There was no input val…

Fix: after 1.8
Fix from $1,600 2017-10-05
Pipeline\ MEDIUM 5.3
CVE-2017-1000089

Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. …

Fix: after 2.5
Fix from $1,600 2017-10-05
Jenkins MEDIUM 5.3
CVE-2014-9634

Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers t…

Fix: after 1.585
Fix from $1,600 2017-09-12
Jenkins MEDIUM 5.3
CVE-2014-9635

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it eas…

Fix: after 1.585
Fix from $1,600 2017-09-12
Jenkins CRITICAL 9.8
CVE-2017-1000362

The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup direct…

Fix: after 1.498
Fix from $2,300 2017-07-17
Tap HIGH 7.5
CVE-2016-4986

Directory traversal vulnerability in the TAP plugin before 1.25 in Jenkins allows remote attackers to read arbitrary files via an unspecified paramet…

Fix: 1.25+
Fix from $1,950 2017-02-09