Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2020-2261 Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitr… Perfecto after 1.17 Fix from $1,9502020-09-16 MEDIUM 6.5 CVE-2020-2254 Jenkins Blue Ocean Plugin 1.23.2 and earlier provides an undocumented feature flag that, when enabled, allows an attacker with Job/Configure or Job/C… Blue Ocean after 1.23.2 Fix from $1,6002020-09-16 MEDIUM 5.4 CVE-2020-2256 Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting… Pipeline Maven Integration after 3.9.2 Fix from $1,6002020-09-16 MEDIUM 5.4 CVE-2020-2257 Jenkins Validating String Parameter Plugin 2.4 and earlier does not escape various user-controlled fields, resulting in a stored cross-site scripting… Validating String Parameter after 2.4 Fix from $1,6002020-09-16 MEDIUM 5.4 CVE-2020-2259 Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vul… Computer Queue after 1.5 Fix from $1,6002020-09-16 MEDIUM 5.4 CVE-2020-2262 Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vuln… Android Lint after 2.6 Fix from $1,6002020-09-16 MEDIUM 5.4 CVE-2020-2263 Jenkins Radiator View Plugin 1.29 and earlier does not escape the full name of the jobs in tooltips, resulting in a stored cross-site scripting (XSS)… Radiator View after 1.29 Fix from $1,6002020-09-16 MEDIUM 5.4 CVE-2020-2264 Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vul… Custom Job Icon after 0.2 Fix from $1,6002020-09-16 MEDIUM 5.4 CVE-2020-2265 Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, resulting in a stored cross-sit… Coverage\/complexity Scatter Plot after 1.1.1 Fix from $1,6002020-09-16 MEDIUM 5.4 CVE-2020-2266 Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting in a stored cross-site scripti… Description Column after 1.3 Fix from $1,6002020-09-16 HIGH 7.1 CVE-2020-2245 Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Valgrind after 0.28 Fix from $1,9502020-09-01 MEDIUM 6.5 CVE-2020-2247 Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Klocwork Analysis after 2020.2.1 Fix from $1,6002020-09-01 MEDIUM 6.5 CVE-2020-2250 Jenkins SoapUI Pro Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files on the Jenkins controller w… Soapui Pro Functional Testing after 1.3 Fix from $1,6002020-09-01 MEDIUM 6.1 CVE-2020-2248 Jenkins JSGames Plugin 0.2 and earlier evaluates part of a URL as code, resulting in a reflected cross-site scripting (XSS) vulnerability. Jsgames after 0.2 Fix from $1,6002020-09-01 MEDIUM 5.4 CVE-2020-2246 Jenkins Valgrind Plugin 0.28 and earlier does not escape content in Valgrind XML reports, resulting in a stored cross-site scripting (XSS) vulnerabil… Valgrind after 0.28 Fix from $1,6002020-09-01 HIGH 8.8 CVE-2020-2240 A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to execute arbitrary SQL scripts. Database after 1.6 Fix from $1,9502020-09-01 HIGH 8.8 CVE-2020-2241 A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect to an attacker-specified dat… Database after 1.6 Fix from $1,9502020-09-01 MEDIUM 6.5 CVE-2020-2242 A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-… Database after 1.6 Fix from $1,6002020-09-01 MEDIUM 5.4 CVE-2020-2238 Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page, resulting in a stored cross… Git Parameter after 0.9.12 Fix from $1,6002020-09-01 MEDIUM 5.4 CVE-2020-2243 Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vu… Cadence Vmanager after 3.0.4 Fix from $1,6002020-09-01 MEDIUM 5.4 CVE-2020-2244 Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scrip… Build Failure Analyzer after 1.27.0 Fix from $1,6002020-09-01 HIGH 7.5 CVE-2020-2232 Jenkins Email Extension Plugin 2.72 and 2.73 transmits and displays the SMTP password in plain text as part of the global Jenkins configuration form,… Email Extension Mitigation only Fix from $1,9502020-08-12 MEDIUM 6.5 CVE-2020-2233 A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to enumerate credenti… Pipeline Maven Integration after 3.8.2 Fix from $1,6002020-08-12 MEDIUM 6.5 CVE-2020-2234 A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to connect to an atta… Pipeline Maven Integration after 3.8.2 Fix from $1,6002020-08-12 MEDIUM 6.5 CVE-2020-2235 A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows attackers to connect to an at… Pipeline Maven Integration after 3.8.2 Fix from $1,6002020-08-12 MEDIUM 5.4 CVE-2020-2229EPSS 7% Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS… Jenkins after 2.251 Fix from $1,6002020-08-12 MEDIUM 5.4 CVE-2020-2230EPSS 83% Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scriptin… Jenkins after 2.251 Fix from $1,6002020-08-12 MEDIUM 5.4 CVE-2020-2231EPSS 5% Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', res… Jenkins after 2.251 Fix from $1,6002020-08-12 MEDIUM 5.4 CVE-2020-2236 Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulner… Yet Another Build Visualizer after 1.11 Fix from $1,6002020-08-12 HIGH 8.8 CVE-2020-2228 Jenkins Gitlab Authentication Plugin 1.5 and earlier does not perform group authorization checks properly, resulting in a privilege escalation vulner… Gitlab Authentication after 1.5 Fix from $1,9502020-07-15