Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2020-2180
Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote co…
Amazon Web Services Serverless Application Model
after 1.2.2
HIGH 7.1
CVE-2020-2178
Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Parasoft Findings
after 10.4.3
MEDIUM 6.5
CVE-2020-2172
Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Code Coverage Api
after 1.1.4
MEDIUM 6.1
CVE-2020-2174
Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output, resulting in a reflected…
Awseb Deployment
after 0.3.19
MEDIUM 5.4
CVE-2020-2173
Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports served by the plugin, resulting …
Gatling
after 1.2.7
MEDIUM 5.4
CVE-2020-2175
Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI, resulting in a stored cross…
Fitnesse
after 1.31
MEDIUM 5.4
CVE-2020-2176
Multiple form validation endpoints in Jenkins useMango Runner Plugin 1.4 and earlier do not escape values received from the useMango service, resulti…
Usemango Runner
after 1.4
HIGH 8.8
CVE-2020-2166
Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in …
Pipeline\
after 1.40
HIGH 8.8
CVE-2020-2167
Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in…
Openshift Pipeline
after 1.0.56
HIGH 8.8
CVE-2020-2168
Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resultin…
Azure Container Service
after 1.0.1
HIGH 8.8
CVE-2020-2171
Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Rapiddeploy
after 4.2
MEDIUM 6.1
CVE-2020-2169
A form validation endpoint in Jenkins Queue cleanup Plugin 1.3 and earlier does not properly escape a query parameter displayed in an error message, …
Queue Cleanup
after 1.3
MEDIUM 5.4
CVE-2020-2161
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions o…
Jenkins
after 2.227
MEDIUM 5.4
CVE-2020-2162
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, res…
Jenkins
after 2.227
MEDIUM 5.4
CVE-2020-2163
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerabi…
Jenkins
after 2.227
MEDIUM 5.4
CVE-2020-2170
Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote server, resulting in a store…
Rapiddeploy
after 4.2
HIGH 8.8
CVE-2020-2160
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that all…
Jenkins
after 2.227
HIGH 8.8
CVE-2020-2158
Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote cod…
Literate
after 1.0
HIGH 8.8
CVE-2020-2159
Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the…
Cryptomove
after 0.1.33
MEDIUM 6.1
CVE-2020-2152
Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation, resulting i…
Subversion Release Manager
after 1.2
MEDIUM 5.5
CVE-2020-2154
Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configuration file on the Jenkins mas…
Zephyr For Jira Test Management
after 1.5
MEDIUM 5.3
CVE-2020-2149
Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form…
Repository Connector
after 1.2.6
MEDIUM 5.3
CVE-2020-2150
Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form,…
Sonar Quality Gates
after 1.3.1
MEDIUM 5.3
CVE-2020-2151
Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potenti…
Quality Gates
after 2.5
MEDIUM 5.3
CVE-2020-2155
Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, …
Openshift Deployer
after 1.2.0
HIGH 7.4
CVE-2020-2146
Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.
Mac
after 1.1.0
HIGH 7.1
CVE-2020-2144
Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Rundeck
after 3.6.6
MEDIUM 6.5
CVE-2020-2139
An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents…
Cobertura
after 1.15
MEDIUM 6.1
CVE-2020-2140EPSS 76%
Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cro…
Audit Trail
after 3.2
MEDIUM 5.5
CVE-2020-2145
Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system.
Zephyr Enterprise Test Management
after 1.9.1