Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2021-21681 Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins controller where they can be … Nomad after 0.7.4 Fix from $1,6002021-08-31 MEDIUM 6.5 CVE-2021-21675 A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or hav… Requests after 2.2.12 Fix from $1,6002021-06-30 MEDIUM 6.1 CVE-2021-21673 Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to… Cas after 1.6.0 Fix from $1,6002021-06-30 HIGH 7.5 CVE-2021-21671 Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login. Jenkins 2.289.2 / 2.300+ Fix from $1,9502021-06-30 CRITICAL 9.8 CVE-2021-21669EPSS 26% Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Generic Webhook Trigger after 1.72 Fix from $2,3002021-06-18 MEDIUM 5.4 CVE-2021-21667EPSS 76% Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in a stored cross-site scripting… Scriptler after 3.2 Fix from $1,6002021-06-16 MEDIUM 5.4 CVE-2021-21668EPSS 76% Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable b… Scriptler after 3.1 Fix from $1,6002021-06-16 MEDIUM 6.1 CVE-2021-21666 Jenkins Kiuwan Plugin 1.6.0 and earlier does not escape query parameters in an error message for a form validation endpoint, resulting in a reflected… Kiuwan after 1.6.0 Fix from $1,6002021-06-10 HIGH 8.8 CVE-2021-21665 A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers to connect to an attacker… Xebialabs Xl Deploy after 10.0.1 Fix from $1,9502021-06-10 MEDIUM 6.5 CVE-2021-21664 An incorrect permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Generic Create permission to connect to … Xebialabs Xl Deploy after 10.0.1 Fix from $1,6002021-06-10 CRITICAL 9.1 CVE-2021-21658 Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Nuget after 1.0 Fix from $2,3002021-05-25 HIGH 8.8 CVE-2021-21657 Jenkins Filesystem Trigger Plugin 0.40 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Filesystem Trigger after 0.40 Fix from $1,9502021-05-25 HIGH 8.1 CVE-2021-21659EPSS 67% Jenkins URLTrigger Plugin 0.48 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Urltrigger after 0.48 Fix from $1,9502021-05-25 MEDIUM 5.4 CVE-2021-21660 Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cross-site scripting (XSS) vuln… Markdown Formatter after 0.1.0 Fix from $1,6002021-05-25 HIGH 7.1 CVE-2021-21652 A cross-site request forgery (CSRF) vulnerability in Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier allows attackers to connect to … Xray Test Management For Jira after 2.4.0 Fix from $1,9502021-05-11 HIGH 7.1 CVE-2021-21655 A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified Perfor… P4 after 1.11.4 Fix from $1,9502021-05-11 HIGH 7.1 CVE-2021-21656 Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Xcode Integration after 2.0.14 Fix from $1,9502021-05-11 MEDIUM 6.1 CVE-2021-21648EPSS 11% Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulting in a reflected cross-site … Credentials after 2.3.18 Fix from $1,6002021-05-11 MEDIUM 5.4 CVE-2021-21649EPSS 73% Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scriptin… Dashboard View after 2.15 Fix from $1,6002021-05-11 HIGH 8.8 CVE-2021-21646 Jenkins Templating Engine Plugin 2.1 and earlier does not protect its pipeline configurations using Script Security Plugin, allowing attackers with J… Templating Engine after 2.1 Fix from $1,9502021-04-21 HIGH 8.1 CVE-2021-21642EPSS 38% Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Config File Provider after 3.7.0 Fix from $1,9502021-04-21 MEDIUM 6.5 CVE-2021-21643 Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with… Config File Provider after 3.7.0 Fix from $1,6002021-04-21 MEDIUM 5.4 CVE-2021-21644 A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration f… Config File Provider after 3.7.0 Fix from $1,6002021-04-21 HIGH 7.5 CVE-2021-28165EPSS 54% In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS f… Jenkins 2.277.3 / 2.286+ Fix from $1,9502021-04-01 HIGH 8.8 CVE-2021-21629 A cross-site request forgery (CSRF) vulnerability in Jenkins Build With Parameters Plugin 1.5 and earlier allows attackers to build a project with at… Build With Parameters after 1.5 Fix from $1,9502021-03-30 HIGH 8.8 CVE-2021-21633 A cross-site request forgery (CSRF) vulnerability in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers to connect to an attack… Owasp Dependency Track after 3.1.0 Fix from $1,9502021-03-30 HIGH 8.8 CVE-2021-21638 A cross-site request forgery (CSRF) vulnerability in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers to connect to an atta… Team Foundation Server after 5.157.1 Fix from $1,9502021-03-30 MEDIUM 6.5 CVE-2021-21632 A missing permission check in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers with Overall/Read permission to connect to an … Owasp Dependency Track after 3.1.0 Fix from $1,6002021-03-30 MEDIUM 6.5 CVE-2021-21634 Jenkins Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file on the Jenkins contr… Jabber \(xmpp\) Notifier And Control after 1.41 Fix from $1,6002021-03-30 MEDIUM 6.5 CVE-2021-21637 A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Read permission to connect to a… Team Foundation Server after 5.157.1 Fix from $1,6002021-03-30