Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2019-16550 A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to ha… Maven after 0.16.1 Fix from $1,9502019-12-17 HIGH 8.8 CVE-2019-16551 A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers to connect to an attacker-specified H… Gerrit Trigger after 2.30.1 Fix from $1,9502019-12-17 MEDIUM 5.4 CVE-2019-16552 A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacke… Gerrit Trigger after 2.30.1 Fix from $1,6002019-12-17 HIGH 8.1 CVE-2019-16549 Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-m… Maven after 0.16.1 Fix from $1,9502019-12-17 CRITICAL 9.9 CVE-2019-16541 Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions, allowing users to select and… Jira after 3.0.10 Fix from $2,3002019-11-21 HIGH 8.8 CVE-2019-16548 A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineCloud#doProvision could be used … Google Compute Engine 4.2.0+ Fix from $1,9502019-11-21 MEDIUM 6.5 CVE-2019-16539 A missing permission check in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete support bundles. Support Core after 2.63 Fix from $1,6002019-11-21 MEDIUM 6.5 CVE-2019-16540 A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete arbitrary file… Support Core after 2.63 Fix from $1,6002019-11-21 MEDIUM 6.5 CVE-2019-16542 Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where … Anchore Container Image Scanner after 1.0.19 Fix from $1,6002019-11-21 MEDIUM 5.9 CVE-2019-16546 Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by the plugin, enabling man-in-th… Google Compute Engine 4.2.0+ Fix from $1,6002019-11-21 MEDIUM 5.5 CVE-2019-16543 Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can … Spira Importer after 3.2.2 Fix from $1,6002019-11-21 HIGH 8.8 CVE-2019-16538 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closure… Script Security after 1.67 Fix from $1,9502019-11-21 MEDIUM 6.1 CVE-2012-4441 Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the … Jenkins 1.466.2 / 1.482+ Fix from $1,6002019-11-18 MEDIUM 6.1 CVE-2012-4440 Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the … Jenkins 1.466.2 / 1.482+ Fix from $1,6002019-11-18 HIGH 8.8 CVE-2012-4438 Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execut… Jenkins 1.466.2 / 1.482+ Fix from $1,9502019-11-18 MEDIUM 6.1 CVE-2012-4439 Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a c… Jenkins 1.466.2 / 1.482+ Fix from $1,6002019-11-18 HIGH 8.8 CVE-2019-10471 A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-specified SSH server using att… Libvirt Slaves after 1.8.5 Fix from $1,9502019-10-23 HIGH 7.8 CVE-2019-10476 Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be view… Zulip after 1.1.0 Fix from $1,9502019-10-23 MEDIUM 6.5 CVE-2019-10469 A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attac… Kubernetes Ci after 1.3 Fix from $1,6002019-10-23 MEDIUM 6.5 CVE-2019-10470 A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to en… Kubernetes Ci after 1.3 Fix from $1,6002019-10-23 MEDIUM 6.5 CVE-2019-10472 A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to an attacker-specified SSH ser… Libvirt Slaves after 1.8.5 Fix from $1,6002019-10-23 MEDIUM 6.1 CVE-2019-10475EPSS 58% A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web page… Build Metrics after 1.3 Fix from $1,6002019-10-23 HIGH 8.8 CVE-2019-10464 A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-specified URL using attacker-… Deploy Weblogic after 4.1 Fix from $1,9502019-10-23 HIGH 8.8 CVE-2019-10468 A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to connect to an attacker-specified… Kubernetes Ci after 1.3 Fix from $1,9502019-10-23 HIGH 8.1 CVE-2019-10462 A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an at… Dynatrace Application Monitoring after 2.1.3 Fix from $1,9502019-10-23 HIGH 8.1 CVE-2019-10466 An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve externa… 360 Fireline after 1.7.2 Fix from $1,9502019-10-23 HIGH 7.8 CVE-2019-10460 Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where… Bitbucket Oauth after 0.9 Fix from $1,9502019-10-23 HIGH 7.8 CVE-2019-10461 Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configuration file on the Jenkins mast… Dynatrace Application Monitoring after 2.1.3 Fix from $1,9502019-10-23 MEDIUM 6.5 CVE-2019-10459 Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in its global configuration file a… Mattermost Notification after 2.7.0 Fix from $1,6002019-10-23 MEDIUM 6.5 CVE-2019-10463 A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permission to connect to an attacker… Dynatrace Application Monitoring after 2.1.4 Fix from $1,6002019-10-23