Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cas HIGH 8.8
CVE-2023-32997

Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login.

Fix: after 1.6.2
Fix from $1,950 2023-05-16
Appspider HIGH 8.8
CVE-2023-32998

A cross-site request forgery (CSRF) vulnerability in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers to connect to an attacker-specified…

Fix: after 1.0.15
Fix from $1,950 2023-05-16
Ns Nd Integration Performance Publisher HIGH 7.5
CVE-2023-33000

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasin…

Fix: after 4.8.0.149
Fix from $1,950 2023-05-16
Hashicorp Vault HIGH 7.5
CVE-2023-33001

Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when…

Fix: after 360.v0a_1c04cf807d
Fix from $1,950 2023-05-16
Testcomplete Support MEDIUM 5.4
CVE-2023-33002

Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stored cross-site scripting (XSS)…

Fix: after 2.8.1
Fix from $1,600 2023-05-16
Wso2 Oauth MEDIUM 5.4
CVE-2023-33005

Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.

Fix: after 1.0
Fix from $1,600 2023-05-16
Wso2 Oauth MEDIUM 5.4
CVE-2023-33006

A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick users into logging in to the…

Fix: after 1.0
Fix from $1,600 2023-05-16
Loadcomplete Support MEDIUM 5.4
CVE-2023-33007

Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cross-site scripting (XSS) vuln…

Fix: after 1.0
Fix from $1,600 2023-05-16
Saml Single Sign On HIGH 8.8
CVE-2023-32991

A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows attackers to send an HTTP reque…

Fix: after 2.0.2
Fix from $1,950 2023-05-16
Saml Single Sign On HIGH 8.8
CVE-2023-32992

Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP r…

Fix: after 2.0.2
Fix from $1,950 2023-05-16
Saml Single Sign On HIGH 8.8
CVE-2023-32995

A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers to send an HTTP POST …

Fix: after 2.0.0
Fix from $1,950 2023-05-16
Azure Vm Agents MEDIUM 6.5
CVE-2023-32990

A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect …

Fix: after 852.v8d35f0960a_43
Fix from $1,600 2023-05-16
File Parameters HIGH 8.8
CVE-2023-32986EPSS 61%

Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameter…

Fix: after 285.287.v4b_7b_29d3469d
Fix from $1,950 2023-05-16
Reverse Proxy Auth HIGH 8.8
CVE-2023-32987

A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier allows attackers to connect to an attacker-s…

Fix: after 1.7.4
Fix from $1,950 2023-05-16
Azure Vm Agents HIGH 8.8
CVE-2023-32989

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers to connect to an …

Fix: after 852.v8d35f0960a_43
Fix from $1,950 2023-05-16
Testng Results MEDIUM 5.4
CVE-2023-32984

Jenkins TestNG Results Plugin 730.v4c5283037693 and earlier does not escape several values that are parsed from TestNG report files and displayed on …

Fix: after 730.v4c5283037693
Fix from $1,600 2023-05-16
Pipeline Utility Steps HIGH 8.8
CVE-2023-32981

An arbitrary file write vulnerability in Jenkins Pipeline Utility Steps Plugin 2.15.2 and earlier allows attackers able to provide crafted archives a…

Fix: after 2.15.2
Fix from $1,950 2023-05-16
Pipeline\ MEDIUM 5.4
CVE-2023-32977

Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-si…

Fix: after 1292.v27d8cc3e2602
Fix from $1,600 2023-05-16
Ansible MEDIUM 5.3
CVE-2023-32983

Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier does not mask extra variables displayed on the configuration form, increasing the potential for…

Fix: after 204.v8191fd551eb_f
Fix from $1,600 2023-05-16
Consul Kv Builder MEDIUM 6.5
CVE-2023-30531

Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing the pot…

Fix: after 2.0.13
Fix from $1,600 2023-04-12
Turboscript MEDIUM 6.5
CVE-2023-30532

A missing permission check in Jenkins TurboScript Plugin 1.3 and earlier allows attackers with Item/Read permission to trigger builds of jobs corresp…

Fix: after 1.3
Fix from $1,600 2023-04-12
Report Portal MEDIUM 6.5
CVE-2023-30526

A missing permission check in Jenkins Report Portal Plugin 0.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-sp…

Fix: after 0.5
Fix from $1,600 2023-04-12
Wso2 Oauth MEDIUM 6.5
CVE-2023-30528

Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for a…

Fix: after 1.0
Fix from $1,600 2023-04-12
Report Portal HIGH 8.8
CVE-2023-30525

A cross-site request forgery (CSRF) vulnerability in Jenkins Report Portal Plugin 0.5 and earlier allows attackers to connect to an attacker-specifie…

Fix: after 0.5
Fix from $1,950 2023-04-12
Assembla Merge Request Builder MEDIUM 5.3
CVE-2023-30521

A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated attackers to trigger builds of …

Fix: after 1.1.13
Fix from $1,600 2023-04-12
Image Tag Parameter MEDIUM 6.5
CVE-2023-30516

Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registr…

Fix: 2.0+
Fix from $1,600 2023-04-12
Quay.io Trigger MEDIUM 5.4
CVE-2023-30520

Jenkins Quay.io trigger Plugin 0.1 and earlier does not limit URL schemes for repository homepage URLs submitted via Quay.io trigger webhooks, result…

Fix: after 0.1
Fix from $1,600 2023-04-12
Neuvector Vulnerability Scanner MEDIUM 5.3
CVE-2023-30517

Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting …

Fix: after 1.22
Fix from $1,600 2023-04-12
Quay.io Trigger MEDIUM 5.3
CVE-2023-30519

A missing permission check in Jenkins Quay.io trigger Plugin 0.1 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding…

Fix: after 0.1
Fix from $1,600 2023-04-12
Azure Key Vault HIGH 7.5
CVE-2023-30514

Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log whe…

Fix: after 187.va_cd5fecd198a
Fix from $1,950 2023-04-12