Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Job Configuration History HIGH 8.8
CVE-2023-41933

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attac…

Fix: after 1229.v3039470161a_d
Fix from $1,950 2023-09-06
Ssh2 Easy HIGH 8.8
CVE-2023-41939

Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly g…

Fix: after 1.4
Fix from $1,950 2023-09-06
Azure Ad HIGH 7.5
CVE-2023-41935

Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking wh…

Fix: after 396.v86ce29279947
Fix from $1,950 2023-09-06
Google Login HIGH 7.5
CVE-2023-41936

Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are eq…

Fix: after 1.7
Fix from $1,950 2023-09-06
Bitbucket Push And Pull Request HIGH 7.5
CVE-2023-41937

Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain …

Fix: after 2.8.3
Fix from $1,950 2023-09-06
Ivy MEDIUM 6.5
CVE-2023-41938

A cross-site request forgery (CSRF) vulnerability in Jenkins Ivy Plugin 2.5 and earlier allows attackers to delete disabled modules.

Fix: after 2.5
Fix from $1,600 2023-09-06
Pipeline Maven Integration MEDIUM 5.3
CVE-2023-41934

Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentia…

Fix: after 1330.v18e473854496
Fix from $1,600 2023-09-06
Job Configuration History MEDIUM 6.5
CVE-2023-41932

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowi…

Fix: after 1227.v7a_79fc4dc01f
Fix from $1,600 2023-09-06
Job Configuration History MEDIUM 5.4
CVE-2023-41931

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not property sanitize or escape the timestamp value from history entrie…

Fix: after 1227.v7a_79fc4dc01f
Fix from $1,600 2023-09-06
Fortify MEDIUM 6.1
CVE-2023-4303

Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method, resulting in an HTML injection vulnerabili…

Fix: 22.2.39+
Fix from $1,600 2023-08-21
Fortify MEDIUM 5.4
CVE-2023-4301

A cross-site request forgery (CSRF) vulnerability in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers to connect to an attacker-specified …

Fix: 22.2.39+
Fix from $1,600 2023-08-21
Maven Artifact Choicelistprovider \(nexus\) MEDIUM 6.5
CVE-2023-40347

Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and earlier does not set the appropriate context for credentials lookup, allowing attac…

Fix: after 1.14
Fix from $1,600 2023-08-16
Shortcut Job MEDIUM 5.4
CVE-2023-40346

Jenkins Shortcut Job Plugin 0.4 and earlier does not escape the shortcut redirection URL, resulting in a stored cross-site scripting (XSS) vulnerabil…

Fix: after 0.4
Fix from $1,600 2023-08-16
Docker Swarm MEDIUM 5.4
CVE-2023-40350

Jenkins Docker Swarm Plugin 1.11 and earlier does not escape values returned from Docker before inserting them into the Docker Swarm Dashboard view, …

Fix: after 1.11
Fix from $1,600 2023-08-16
Gogs MEDIUM 5.3
CVE-2023-40348

The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its outp…

Fix: after 1.0.15
Fix from $1,600 2023-08-16
Gogs MEDIUM 5.3
CVE-2023-40349

Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger…

Fix: after 1.0.15
Fix from $1,600 2023-08-16
Folders HIGH 8.8
CVE-2023-40336

A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy folders.

Fix: after 6.846.v23698686f0f6
Fix from $1,950 2023-08-16
Blue Ocean HIGH 8.8
CVE-2023-40341

A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and earlier allows attackers to connect to an attacker-specifie…

Fix: after 1.27.5
Fix from $1,950 2023-08-16
Config File Provider HIGH 7.5
CVE-2023-40339

Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configurat…

Fix: after 952.va_544a_6234b_46
Fix from $1,950 2023-08-16
Node.js HIGH 7.5
CVE-2023-40340

Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in the Npm config file in Pipelin…

Fix: after 1.6.0
Fix from $1,950 2023-08-16
Delphix MEDIUM 6.5
CVE-2023-40345

Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission…

Fix: after 3.0.2
Fix from $1,600 2023-08-16
Tuleap Authentication MEDIUM 5.9
CVE-2023-40343

Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing…

Fix: after 1.1.20
Fix from $1,600 2023-08-16
Flaky Test Handler MEDIUM 5.4
CVE-2023-40342

Jenkins Flaky Test Handler Plugin 1.2.2 and earlier does not escape JUnit test contents when showing them on the Jenkins UI, resulting in a stored cr…

Fix: after 1.2.2
Fix from $1,600 2023-08-16
Servicenow Devops HIGH 7.5
CVE-2023-3442

A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully…

Fix: 1.38.1+
Fix from $1,950 2023-07-26
Servicenow Devops MEDIUM 6.5
CVE-2023-3414

A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited success…

Fix: 1.38.1+
Fix from $1,600 2023-07-26
Gradle MEDIUM 6.5
CVE-2023-39152

Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i.e., replaced with asterisks) …

Mitigation only
Fix from $1,600 2023-07-26
Qualys Web App Scanning Connector MEDIUM 6.5
CVE-2023-39154

Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with global Item/Configure permiss…

Fix: after 2.0.10
Fix from $1,600 2023-07-26
Jenkins MEDIUM 5.4
CVE-2023-39151

Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, re…

Fix: after 2.415
Fix from $1,600 2023-07-26
Gitlab Authentication MEDIUM 5.4
CVE-2023-39153

A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into log…

Fix: after 1.17.1
Fix from $1,600 2023-07-26
Chef Identity MEDIUM 5.3
CVE-2023-39155

Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and captu…

Fix: after 2.0.3
Fix from $1,600 2023-07-26