Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nexus Platform HIGH 8.8
CVE-2023-50768

A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-s…

Fix: after 3.18.0-03
Fix from $1,950 2023-12-13
Scriptler HIGH 8.1
CVE-2023-50764

Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing attackers with Sc…

Fix: after 342.v6a_89fd40f466
Fix from $1,950 2023-12-13
Nexus Platform MEDIUM 5.4
CVE-2023-50767

Missing permission checks in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allow attackers with Overall/Read permission to send an HTTP request…

Fix: after 3.18.0-03
Fix from $1,600 2023-12-13
Matlab CRITICAL 9.8
CVE-2023-49654

Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller f…

Fix: 2.11.1+
Fix from $2,300 2023-11-29
Matlab CRITICAL 9.8
CVE-2023-49656

Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: 2.11.1+
Fix from $2,300 2023-11-29
Matlab HIGH 8.8
CVE-2023-49655

A cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11.0 and earlier allows attackers to have Jenkins parse an XML file from…

Fix: 2.11.1+
Fix from $1,950 2023-11-29
Neuvector Vulnerability Scanner HIGH 8.8
CVE-2023-49673

A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to a…

Fix: 2.2 / 2.11.1+
Fix from $1,950 2023-11-29
Jira MEDIUM 6.5
CVE-2023-49653

Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission t…

Fix: after 3.11
Fix from $1,600 2023-11-29
Cloudbees Cd HIGH 8.1
CVE-2023-46654

Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of th…

Fix: after 1.1.32
Fix from $1,950 2023-10-25
Lambdatest Automation MEDIUM 6.5
CVE-2023-46653

Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, potentially resulting in its exp…

Fix: 1.21.0+
Fix from $1,600 2023-10-25
Cloudbees Cd MEDIUM 6.5
CVE-2023-46655

Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which artifacts are published during…

Fix: after 1.1.32
Fix from $1,600 2023-10-25
Edgewall Trac MEDIUM 5.4
CVE-2023-46659

Jenkins Edgewall Trac Plugin 1.13 and earlier does not escape the Trac website URL on the build page, resulting in a stored cross-site scripting (XSS…

Fix: after 1.13
Fix from $1,600 2023-10-25
Multibranch Scan Webhook Trigger MEDIUM 5.3
CVE-2023-46656

Jenkins Multibranch Scan Webhook Trigger Plugin 1.0.9 and earlier uses a non-constant time comparison function when checking whether the provided and…

Fix: after 1.0.9
Fix from $1,600 2023-10-25
Gogs MEDIUM 5.3
CVE-2023-46657

Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are…

Fix: after 1.0.15
Fix from $1,600 2023-10-25
Msteams Webhook Trigger MEDIUM 5.3
CVE-2023-46658

Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected…

Mitigation only
Fix from $1,600 2023-10-25
Zanata MEDIUM 5.3
CVE-2023-46660

Jenkins Zanata Plugin 0.6 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token hash…

Fix: after 0.6
Fix from $1,600 2023-10-25
Warnings MEDIUM 6.5
CVE-2023-46651

Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permis…

Fix: after 10.5.0
Fix from $1,600 2023-10-25
GitHub MEDIUM 5.4
CVE-2023-46650

Jenkins GitHub Plugin 1.37.3 and earlier does not escape the GitHub project URL on the build page when showing changes, resulting in a stored cross-s…

Fix: after 1.37.3
Fix from $1,600 2023-10-25
Jenkins HIGH 7.5
CVE-2023-36478

Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an i…

Fix: 2.414.3 / 2.428+
Fix from $1,950 2023-10-10
Build Failure Analyzer HIGH 8.8
CVE-2023-43500

A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to connect to an attack…

Fix: 2.4.2+
Fix from $1,950 2023-09-20
Build Failure Analyzer MEDIUM 6.5
CVE-2023-43501

A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read permission to connect to an …

Fix: 2.4.2+
Fix from $1,600 2023-09-20
Jenkins HIGH 8.8
CVE-2023-43496

Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly …

Fix: 2.414.2 / 2.424+
Fix from $1,950 2023-09-20
Jenkins HIGH 8.1
CVE-2023-43497

In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default…

Fix: 2.414.2 / 2.424+
Fix from $1,950 2023-09-20
Jenkins HIGH 8.1
CVE-2023-43498

In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the default s…

Fix: 2.414.2 / 2.424+
Fix from $1,950 2023-09-20
Jenkins MEDIUM 5.4
CVE-2023-43495

Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of 'ExpandableDetailsNote', resul…

Fix: 2.414.2 / 2.424+
Fix from $1,600 2023-09-20
Build Failure Analyzer MEDIUM 5.4
CVE-2023-43499

Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in a stored cross-site scripting…

Fix: 2.4.2+
Fix from $1,600 2023-09-20
Assembla Auth HIGH 8.8
CVE-2023-41945

Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to…

Fix: after 1.14
Fix from $1,950 2023-09-06
Aws Codecommit Trigger MEDIUM 6.5
CVE-2023-41943

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Rea…

Fix: after 3.0.12
Fix from $1,600 2023-09-06
Aws Codecommit Trigger MEDIUM 6.1
CVE-2023-41944

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not escape the queue name parameter passed to a form validation URL, when rendering an …

Fix: after 3.0.12
Fix from $1,600 2023-09-06
Tap MEDIUM 5.4
CVE-2023-41940

Jenkins TAP Plugin 2.3 and earlier does not escape TAP file contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by a…

Fix: after 2.3
Fix from $1,600 2023-09-06