Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2020-2180 Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote co… Amazon Web Services Serverless Application Model after 1.2.2 Fix from $1,9502020-04-16 HIGH 7.1 CVE-2020-2178 Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Parasoft Findings after 10.4.3 Fix from $1,9502020-04-16 MEDIUM 6.5 CVE-2020-2172 Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Code Coverage Api after 1.1.4 Fix from $1,6002020-04-07 MEDIUM 6.1 CVE-2020-2174 Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output, resulting in a reflected… Awseb Deployment after 0.3.19 Fix from $1,6002020-04-07 MEDIUM 5.4 CVE-2020-2173 Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports served by the plugin, resulting … Gatling after 1.2.7 Fix from $1,6002020-04-07 MEDIUM 5.4 CVE-2020-2175 Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI, resulting in a stored cross… Fitnesse after 1.31 Fix from $1,6002020-04-07 MEDIUM 5.4 CVE-2020-2176 Multiple form validation endpoints in Jenkins useMango Runner Plugin 1.4 and earlier do not escape values received from the useMango service, resulti… Usemango Runner after 1.4 Fix from $1,6002020-04-07 HIGH 8.8 CVE-2020-2166 Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in … Pipeline\ after 1.40 Fix from $1,9502020-03-25 HIGH 8.8 CVE-2020-2167 Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in… Openshift Pipeline after 1.0.56 Fix from $1,9502020-03-25 HIGH 8.8 CVE-2020-2168 Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resultin… Azure Container Service after 1.0.1 Fix from $1,9502020-03-25 HIGH 8.8 CVE-2020-2171 Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Rapiddeploy after 4.2 Fix from $1,9502020-03-25 MEDIUM 6.1 CVE-2020-2169 A form validation endpoint in Jenkins Queue cleanup Plugin 1.3 and earlier does not properly escape a query parameter displayed in an error message, … Queue Cleanup after 1.3 Fix from $1,6002020-03-25 MEDIUM 5.4 CVE-2020-2161 Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions o… Jenkins after 2.227 Fix from $1,6002020-03-25 MEDIUM 5.4 CVE-2020-2162 Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, res… Jenkins after 2.227 Fix from $1,6002020-03-25 MEDIUM 5.4 CVE-2020-2163 Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerabi… Jenkins after 2.227 Fix from $1,6002020-03-25 MEDIUM 5.4 CVE-2020-2170 Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote server, resulting in a store… Rapiddeploy after 4.2 Fix from $1,6002020-03-25 HIGH 8.8 CVE-2020-2160 Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that all… Jenkins after 2.227 Fix from $1,9502020-03-25 HIGH 8.8 CVE-2020-2158 Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote cod… Literate after 1.0 Fix from $1,9502020-03-09 HIGH 8.8 CVE-2020-2159 Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the… Cryptomove after 0.1.33 Fix from $1,9502020-03-09 MEDIUM 6.1 CVE-2020-2152 Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation, resulting i… Subversion Release Manager after 1.2 Fix from $1,6002020-03-09 MEDIUM 5.5 CVE-2020-2154 Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configuration file on the Jenkins mas… Zephyr For Jira Test Management after 1.5 Fix from $1,6002020-03-09 MEDIUM 5.3 CVE-2020-2149 Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form… Repository Connector after 1.2.6 Fix from $1,6002020-03-09 MEDIUM 5.3 CVE-2020-2150 Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form,… Sonar Quality Gates after 1.3.1 Fix from $1,6002020-03-09 MEDIUM 5.3 CVE-2020-2151 Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potenti… Quality Gates after 2.5 Fix from $1,6002020-03-09 MEDIUM 5.3 CVE-2020-2155 Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, … Openshift Deployer after 1.2.0 Fix from $1,6002020-03-09 HIGH 7.4 CVE-2020-2146 Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks. Mac after 1.1.0 Fix from $1,9502020-03-09 HIGH 7.1 CVE-2020-2144 Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Rundeck after 3.6.6 Fix from $1,9502020-03-09 MEDIUM 6.5 CVE-2020-2139 An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents… Cobertura after 1.15 Fix from $1,6002020-03-09 MEDIUM 6.1 CVE-2020-2140EPSS 76% Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cro… Audit Trail after 3.2 Fix from $1,6002020-03-09 MEDIUM 5.5 CVE-2020-2145 Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system. Zephyr Enterprise Test Management after 1.9.1 Fix from $1,6002020-03-09