Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bazaar MEDIUM 5.3
CVE-2023-39156

A cross-site request forgery (CSRF) vulnerability in Jenkins Bazaar Plugin 1.22 and earlier allows attackers to delete previously created Bazaar SCM …

Fix: after 1.22
Fix from $1,600 2023-07-26
Benchmark Evaluator HIGH 8.8
CVE-2023-37962

A cross-site request forgery (CSRF) vulnerability in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers to connect to an attacker-…

Fix: after 1.0.1
Fix from $1,950 2023-07-12
Elasticbox Ci HIGH 8.8
CVE-2023-37964

A cross-site request forgery (CSRF) vulnerability in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers to connect to an attacker-specif…

Fix: after 5.0.1
Fix from $1,950 2023-07-12
Elasticbox Ci HIGH 7.1
CVE-2023-37965

A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-…

Fix: after 5.0.1
Fix from $1,950 2023-07-12
Benchmark Evaluator MEDIUM 5.4
CVE-2023-37963

A missing permission check in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to connect to an att…

Fix: after 1.0.1
Fix from $1,600 2023-07-12
Openshift Login HIGH 8.8
CVE-2023-37946

Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login.

Fix: after 1.1.0.230.v5d7030b_f5432
Fix from $1,950 2023-07-12
Pipeline Restful Api HIGH 8.8
CVE-2023-37957

A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline restFul API Plugin 0.11 and earlier allows attackers to connect to an attacker-…

Fix: after 0.11
Fix from $1,950 2023-07-12
Sumologic Publisher HIGH 8.8
CVE-2023-37958

A cross-site request forgery (CSRF) vulnerability in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attackers to connect to an attacker-…

Fix: after 2.2.1
Fix from $1,950 2023-07-12
Assembla HIGH 8.8
CVE-2023-37961

A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Auth Plugin 1.14 and earlier allows attackers to trick users into logging in to…

Fix: after 1.14
Fix from $1,950 2023-07-12
Orka By Macstadium HIGH 7.1
CVE-2023-37949

A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read permission to connect to an attac…

Fix: 1.34+
Fix from $1,950 2023-07-12
External Monitor Job Type MEDIUM 6.5
CVE-2023-37942

Jenkins External Monitor Job Type Plugin 206.v9a_94ff0b_4a_10 and earlier does not configure its XML parser to prevent XML external entity (XXE) atta…

Fix: after 206.v9a_94ff0b_4a_10
Fix from $1,600 2023-07-12
Datadog MEDIUM 6.5
CVE-2023-37944

A missing permission check in Jenkins Datadog Plugin 5.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specif…

Fix: 5.4.2+
Fix from $1,600 2023-07-12
Mabl MEDIUM 6.5
CVE-2023-37951

Jenkins mabl Plugin 0.0.46 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission…

Fix: after 0.0.46
Fix from $1,600 2023-07-12
Mabl MEDIUM 6.5
CVE-2023-37952

A cross-site request forgery (CSRF) vulnerability in Jenkins mabl Plugin 0.0.46 and earlier allows attackers to connect to an attacker-specified URL …

Fix: after 0.0.46
Fix from $1,600 2023-07-12
Mabl MEDIUM 6.5
CVE-2023-37953

A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifie…

Fix: after 0.0.46
Fix from $1,600 2023-07-12
Test Results Aggregator MEDIUM 6.5
CVE-2023-37955

A cross-site request forgery (CSRF) vulnerability in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers to connect to an atta…

Fix: after 1.2.13
Fix from $1,600 2023-07-12
Test Results Aggregator MEDIUM 6.5
CVE-2023-37956

A missing permission check in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers with Overall/Read permission to connect to a…

Fix: after 1.2.13
Fix from $1,600 2023-07-12
Sumologic Publisher MEDIUM 6.5
CVE-2023-37959

A missing permission check in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attackers with Overall/Read permission to connect to an att…

Fix: after 2.2.1
Fix from $1,600 2023-07-12
Mathworks Polyspace MEDIUM 6.5
CVE-2023-37960

Jenkins MathWorks Polyspace Plugin 1.0.5 and earlier allows attackers with Item/Configure permission to send emails with arbitrary files from the Jen…

Fix: after 1.0.5
Fix from $1,600 2023-07-12
Openshift Login MEDIUM 6.1
CVE-2023-37947

Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing t…

Fix: 1.1.0.230.v5d7030b_f5432+
Fix from $1,600 2023-07-12
Active Directory MEDIUM 5.9
CVE-2023-37943

Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active d…

Fix: after 2.30
Fix from $1,600 2023-07-12
Aws Codecommit Trigger MEDIUM 6.5
CVE-2023-35147

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attack…

Fix: after 3.0.12
Fix from $1,600 2023-06-14
Digital.ai App Management Publisher MEDIUM 6.5
CVE-2023-35148

A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect t…

Fix: after 2.6
Fix from $1,600 2023-06-14
Digital.ai App Management Publisher MEDIUM 6.5
CVE-2023-35149

A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to con…

Fix: after 2.6
Fix from $1,600 2023-06-14
Maven Repository Server MEDIUM 5.4
CVE-2023-35144

Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape project and build display names on the Build Artifacts As Maven Repository pa…

Fix: after 1.10
Fix from $1,600 2023-06-14
Sonargraph Integration MEDIUM 5.4
CVE-2023-35145

Jenkins Sonargraph Integration Plugin 5.0.1 and earlier does not escape the file path and the project name for the Log file field form validation, re…

Fix: after 5.0.1
Fix from $1,600 2023-06-14
Template Workflows MEDIUM 5.4
CVE-2023-35146

Jenkins Template Workflows Plugin 41.v32d86a_313b_4a and earlier does not escape names of jobs used as buildings blocks for Template Workflow Job, re…

Fix: after 41.v32d86a_313b_4a
Fix from $1,600 2023-06-14
Checkmarx HIGH 8.1
CVE-2023-35142

Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.

Fix: after 2023.4.3
Fix from $1,950 2023-06-14
Jenkins HIGH 8.0
CVE-2023-35141

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includ…

Fix: 2.400 / 2.401.1+
Fix from $1,950 2023-06-14
Maven Repository Server MEDIUM 5.4
CVE-2023-35143

Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape the versions of build artifacts on the Build Artifacts As Maven Repository pa…

Fix: after 1.10
Fix from $1,600 2023-06-14