Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2020-2314 Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be … Appspider after 1.0.12 Fix from $1,6002020-11-04 MEDIUM 5.4 CVE-2020-2316 Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site script… Static Analysis Utilities after 1.96 Fix from $1,6002020-11-04 MEDIUM 5.4 CVE-2020-2317 Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulner… Findbugs after 5.0.0 Fix from $1,6002020-11-04 CRITICAL 9.8 CVE-2020-2300 Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log i… Active Directory after 2.19 Fix from $2,3002020-11-04 CRITICAL 9.8 CVE-2020-2301 Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that u… Active Directory after 2.19 Fix from $2,3002020-11-04 MEDIUM 6.5 CVE-2020-2304 Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Subversion after 2.13.1 Fix from $1,6002020-11-04 MEDIUM 6.5 CVE-2020-2305 Jenkins Mercurial Plugin 2.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Mercurial after 2.11 Fix from $1,6002020-11-04 CRITICAL 9.8 CVE-2020-2299 Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password. Active Directory after 2.19 Fix from $2,3002020-11-04 MEDIUM 6.5 CVE-2020-2298 Jenkins Nerrvana Plugin 1.02.06 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Nerrvana after 1.02.06 Fix from $1,6002020-10-08 HIGH 8.8 CVE-2020-2286 Jenkins Role-based Authorization Strategy Plugin 3.0 and earlier does not properly invalidate a permission cache when the configuration is changed, r… Role Based Authorization Strategy after 3.0 Fix from $1,9502020-10-08 MEDIUM 6.5 CVE-2020-2293 Jenkins Persona Plugin 2.4 and earlier allows users with Overall/Read permission to read arbitrary files on the Jenkins controller. Persona after 2.4 Fix from $1,6002020-10-08 MEDIUM 5.4 CVE-2020-2289 Jenkins Active Choices Plugin 2.4 and earlier does not escape the name and description of build parameters, resulting in a stored cross-site scriptin… Active Choices after 2.4 Fix from $1,6002020-10-08 MEDIUM 5.4 CVE-2020-2290 Jenkins Active Choices Plugin 2.4 and earlier does not escape some return values of sandboxed scripts for Reactive Reference Parameters, resulting in… Active Choices after 2.4 Fix from $1,6002020-10-08 MEDIUM 5.4 CVE-2020-2292 Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cross-site scripting (XSS) vuln… Release after 2.10.2 Fix from $1,6002020-10-08 MEDIUM 5.3 CVE-2020-2287 Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework… Audit Trail after 3.6 Fix from $1,6002020-10-08 MEDIUM 5.3 CVE-2020-2288 In Jenkins Audit Trail Plugin 3.6 and earlier, the default regular expression pattern could be bypassed in many cases by adding a suffix to the URL t… Audit Trail after 3.6 Fix from $1,6002020-10-08 CRITICAL 9.9 CVE-2020-2279 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.74 and earlier allows attackers with permission to define sandboxed scripts to pro… Script Security after 1.74 Fix from $2,3002020-09-23 HIGH 8.8 CVE-2020-2280 A cross-site request forgery (CSRF) vulnerability in Jenkins Warnings Plugin 5.0.1 and earlier allows attackers to execute arbitrary code. Warnings after 5.0.1 Fix from $1,9502020-09-23 HIGH 7.1 CVE-2020-2284 Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Liquibase Runner after 1.4.5 Fix from $1,9502020-09-23 MEDIUM 5.4 CVE-2020-2281 A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers to reserve, unreserve, unlock… Lockable Resources after 2.8 Fix from $1,6002020-09-23 MEDIUM 5.4 CVE-2020-2283 Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability … Liquibase Runner after 1.4.5 Fix from $1,6002020-09-23 HIGH 8.8 CVE-2020-2268 A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain access to some metadata of any a… MongoDB after 1.3 Fix from $1,9502020-09-16 HIGH 8.8 CVE-2020-2276 Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing attackers with Job/Configure per… Selection Tasks after 1.0 Fix from $1,9502020-09-16 MEDIUM 6.5 CVE-2020-2275 Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, a… Copy Data To Workspace after 1.0 Fix from $1,6002020-09-16 MEDIUM 6.5 CVE-2020-2277 Jenkins Storable Configs Plugin 1.0 and earlier allows users with Job/Read permission to read arbitrary files on the Jenkins controller. Storable Configs after 1.0 Fix from $1,6002020-09-16 MEDIUM 6.5 CVE-2020-2278 Jenkins Storable Configs Plugin 1.0 and earlier does not restrict the user-specified file name, allowing attackers with Job/Configure permission to r… Storable Configs after 1.0 Fix from $1,6002020-09-16 MEDIUM 5.5 CVE-2020-2274 Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it … Elastest after 1.2.1 Fix from $1,6002020-09-16 MEDIUM 5.4 CVE-2020-2269 Jenkins chosen-views-tabbar Plugin 1.2 and earlier does not escape view names in the dropdown to select views, resulting in a stored cross-site scrip… Chosen Views Tabbar after 1.2 Fix from $1,6002020-09-16 MEDIUM 5.4 CVE-2020-2270 Jenkins ClearCase Release Plugin 0.3 and earlier does not escape the composite baseline in badge tooltip, resulting in a stored cross-site scripting … Clearcase Release after 0.3 Fix from $1,6002020-09-16 MEDIUM 5.4 CVE-2020-2271 Jenkins Locked Files Report Plugin 1.6 and earlier does not escape locked files' names in tooltips, resulting in a stored cross-site scripting (XSS) … Locked Files Report after 1.6 Fix from $1,6002020-09-16