Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2020-2143 Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentiall… Logstash after 2.3.1 Fix from $1,6002020-03-09 HIGH 8.8 CVE-2020-2134 Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor… Script Security after 1.70 Fix from $1,9502020-03-09 HIGH 8.8 CVE-2020-2135 Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement Gr… Script Security after 1.70 Fix from $1,9502020-03-09 HIGH 7.1 CVE-2020-2138 Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Cobertura after 1.15 Fix from $1,9502020-03-09 MEDIUM 5.4 CVE-2020-2136 Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a… Git after 4.2.0 Fix from $1,6002020-03-09 MEDIUM 6.5 CVE-2020-2129 Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be vi… Eagle Tester after 1.0.9 Fix from $1,6002020-02-12 MEDIUM 6.5 CVE-2020-2130 Jenkins Harvest SCM Plugin 0.5.1 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be vie… Harvest Scm after 0.5.1 Fix from $1,6002020-02-12 MEDIUM 6.5 CVE-2020-2131 Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by u… Harvest Scm after 0.5.1 Fix from $1,6002020-02-12 MEDIUM 6.5 CVE-2020-2132 Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can… Parasoft Environment Manager after 2.14 Fix from $1,6002020-02-12 MEDIUM 6.5 CVE-2020-2133 Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users w… Applatix after 1.1 Fix from $1,6002020-02-12 HIGH 8.8 CVE-2020-2115 Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks. Nunit after 0.25 Fix from $1,9502020-02-12 HIGH 8.8 CVE-2020-2116 A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker… Pipeline Github Notify Step after 1.0.4 Fix from $1,9502020-02-12 HIGH 8.8 CVE-2020-2120 Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks. Fitnesse after 1.30 Fix from $1,9502020-02-12 HIGH 8.8 CVE-2020-2121 Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulti… Google Kubernetes Engine after 0.8.0 Fix from $1,9502020-02-12 HIGH 8.8 CVE-2020-2123 Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote cod… Radargun after 1.7 Fix from $1,9502020-02-12 MEDIUM 5.4 CVE-2020-2122 Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site … Brakeman after 0.12 Fix from $1,6002020-02-12 MEDIUM 5.3 CVE-2020-2119 Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentiall… Azure Ad after 1.1.2 Fix from $1,6002020-02-12 HIGH 8.8 CVE-2020-2109 Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter expressions in CPS-transformed m… Pipeline\ after 2.78 Fix from $1,9502020-02-12 HIGH 8.8 CVE-2020-2110 Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST trans… Script Security after 1.69 Fix from $1,9502020-02-12 HIGH 7.5 CVE-2020-2114 Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, poten… S3 Publisher after 0.11.4 Fix from $1,9502020-02-12 MEDIUM 5.4 CVE-2020-2111 Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting i… Subversion after 2.13.0 Fix from $1,6002020-02-12 MEDIUM 5.4 CVE-2020-2112 Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulner… Git Parameter after 0.9.11 Fix from $1,6002020-02-12 MEDIUM 5.4 CVE-2020-2113 Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnera… Git Parameter after 0.9.11 Fix from $1,6002020-02-12 HIGH 8.6 CVE-2020-2099 Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthor… Jenkins after 2.218 Fix from $1,9502020-01-29 HIGH 7.6 CVE-2020-2108 Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Jo… Websphere Deployer after 1.6.1 Fix from $1,9502020-01-29 MEDIUM 5.8 CVE-2020-2100 Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848. Jenkins after 2.218 Fix from $1,6002020-01-29 MEDIUM 5.4 CVE-2020-2103EPSS 7% Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page. Jenkins after 2.218 Fix from $1,6002020-01-29 MEDIUM 5.4 CVE-2020-2105 REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks. Jenkins after 2.218 Fix from $1,6002020-01-29 MEDIUM 5.4 CVE-2020-2106 Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view, resulting in a stored XSS vu… Code Coverage Api after 1.1.2 Fix from $1,6002020-01-29 MEDIUM 5.3 CVE-2020-2101 Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could pot… Jenkins after 2.218 Fix from $1,6002020-01-29