Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thycotic Devops Secrets Vault HIGH 7.5
CVE-2023-30515

Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log whe…

Fix: after 1.0.0
Fix from $1,950 2023-04-12
Kubernetes HIGH 7.5
CVE-2023-30513

Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push…

Fix: after 3909.v1f2c633e8590
Fix from $1,950 2023-04-12
Convert To Pipeline CRITICAL 9.8
CVE-2023-28677

Jenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build Environment, Build Steps, and…

Fix: after 1.0
Fix from $2,300 2023-04-02
Octoperf Load Testing HIGH 8.8
CVE-2023-28674

A cross-site request forgery (CSRF) vulnerability in Jenkins OctoPerf Load Testing Plugin Plugin 4.5.2 and earlier allows attackers to connect to a p…

Fix: after 4.5.2
Fix from $1,950 2023-04-02
Convert To Pipeline HIGH 8.8
CVE-2023-28676

A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers to create a Pipeline based o…

Fix: after 1.0
Fix from $1,950 2023-04-02
Visual Studio Code Metrics HIGH 8.2
CVE-2023-28681

Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.7
Fix from $1,950 2023-04-02
Performance Publisher HIGH 8.2
CVE-2023-28682

Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 8.09
Fix from $1,950 2023-04-02
Phabricator Differential HIGH 8.2
CVE-2023-28683

Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2.1.5
Fix from $1,950 2023-04-02
Crap4j HIGH 7.5
CVE-2023-28680

Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.9
Fix from $1,950 2023-04-02
Remote Jobs View MEDIUM 6.5
CVE-2023-28684

Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.0.3
Fix from $1,600 2023-04-02
Cppcheck MEDIUM 5.4
CVE-2023-28678

Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on the Jenkins UI, resulting in a …

Fix: after 1.26
Fix from $1,600 2023-04-02
Mashup Portlets MEDIUM 5.4
CVE-2023-28679

Jenkins Mashup Portlets Plugin 1.1.2 and earlier provides the "Generic JS Portlet" feature that lets a user populate a portlet using a custom JavaScr…

Fix: after 1.1.2
Fix from $1,600 2023-04-02
Role Based Authorization Strategy CRITICAL 9.8
CVE-2023-28668

Jenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.

Fix: after 587.v2872c41fa_e51
Fix from $2,300 2023-04-02
Octoperf Load Testing MEDIUM 6.5
CVE-2023-28672

Jenkins OctoPerf Load Testing Plugin Plugin 4.5.1 and earlier does not perform a permission check in a connection test HTTP endpoint, allowing attack…

Fix: after 4.5.1
Fix from $1,600 2023-04-02
Jacoco MEDIUM 5.4
CVE-2023-28669

Jenkins JaCoCo Plugin 3.3.2 and earlier does not escape class and method names shown on the UI, resulting in a stored cross-site scripting (XSS) vuln…

Fix: after 3.3.2
Fix from $1,600 2023-04-02
Pipeline Aggregator View MEDIUM 5.4
CVE-2023-28670

Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL in inline JavaScript, resulti…

Fix: after 1.13
Fix from $1,600 2023-04-02
Absint A3 HIGH 7.1
CVE-2023-28685

Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.1.0
Fix from $1,950 2023-03-22
Jenkins CRITICAL 9.6
CVE-2023-27898

Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on wh…

Fix: 2.375.4 / 2.394+
Fix from $2,300 2023-03-10
Update Center2 CRITICAL 9.6
CVE-2023-27905

Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a st…

Mitigation only
Fix from $2,300 2023-03-10
Jenkins HIGH 7.5
CVE-2023-27900

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request par…

Fix: 2.375.4 / 2.394+
Fix from $1,950 2023-03-10
Jenkins HIGH 7.5
CVE-2023-27901

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request par…

Fix: 2.375.4 / 2.394+
Fix from $1,950 2023-03-10
Jenkins HIGH 7.0
CVE-2023-27899

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly…

Fix: 2.375.4 / 2.394+
Fix from $1,950 2023-03-10
Jenkins MEDIUM 5.3
CVE-2023-27904

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error stack trace on agent-related pages when agent connections are broken, potentially …

Fix: 2.375.4 / 2.394+
Fix from $1,600 2023-03-10
Email Extension CRITICAL 9.9
CVE-2023-25765

In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attack…

Fix: 2.93.1+
Fix from $2,300 2023-02-15
Azure Credentials HIGH 8.8
CVE-2023-25767

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers to connect to an…

Fix: 254.v64da_8176c83a+
Fix from $1,950 2023-02-15
Azure Credentials MEDIUM 6.5
CVE-2023-25768

A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to connect…

Fix: 254.v64da_8176c83a+
Fix from $1,600 2023-02-15
Junit MEDIUM 5.4
CVE-2023-25761

Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-sit…

Fix: after 1166.va_436e268e972
Fix from $1,600 2023-02-15
Pipeline\ MEDIUM 5.4
CVE-2023-25762EPSS 81%

Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pipeline Snippet Generator, res…

Fix: after 2.18
Fix from $1,600 2023-02-15
Email Extension MEDIUM 5.4
CVE-2023-25763

Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site …

Fix: 2.93.1+
Fix from $1,600 2023-02-15
Email Extension MEDIUM 5.4
CVE-2023-25764

Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during t…

Fix: 2.93.1+
Fix from $1,600 2023-02-15