Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2019-10467 Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Exten… Sonar Gerrit after 2.3 Fix from $1,6002019-10-23 CRITICAL 9.9 CVE-2019-10458 Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to exec… Puppet Enterprise Pipeline after 1.3.1 Fix from $2,3002019-10-16 HIGH 7.8 CVE-2019-10453 Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with a… Delphix after 2.0.4 Fix from $1,9502019-10-16 HIGH 8.8 CVE-2019-10440 Jenkins NeoLoad Plugin 2.2.5 and earlier stored credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins m… Neoload after 2.2.5 Fix from $1,9502019-10-16 HIGH 8.8 CVE-2019-10443 Jenkins iceScrum Plugin 1.1.4 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by … Icescrum after 1.1.4 Fix from $1,9502019-10-16 HIGH 8.8 CVE-2019-10448 Jenkins Extensive Testing Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with … Extensive Testing Mitigation only Fix from $1,9502019-10-16 HIGH 8.8 CVE-2019-10449 Jenkins Fortify on Demand Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with … Fortify On Demand after 4.0.0 Fix from $1,9502019-10-16 HIGH 8.2 CVE-2019-10446 Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM. Cadence Vmanager after 2.7.0 Fix from $1,9502019-10-16 MEDIUM 6.5 CVE-2019-10444 Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connections to HP ALM. Bumblebee Hp Alm after 4.1.3 Fix from $1,6002019-10-16 HIGH 8.8 CVE-2019-10437 A cross-site request forgery vulnerability in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers to connect to an attack… Crx Content Package Deployer after 1.8.1 Fix from $1,9502019-10-16 MEDIUM 6.5 CVE-2019-10436 An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credenti… Google Oauth Credentials after 0.9 Fix from $1,6002019-10-16 MEDIUM 6.5 CVE-2019-10438 A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers with Overall/Read permission to connect… Crx Content Package Deployer after 1.8.1 Fix from $1,6002019-10-16 HIGH 7.5 CVE-2019-10435 Jenkins SourceGear Vault Plugin transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exp… Sourcegear Vault after 1.1.1 Fix from $1,9502019-10-01 HIGH 7.5 CVE-2019-10434 Jenkins LDAP Email Plugin transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in t… Ldap Email after 0.8 Fix from $1,9502019-10-01 MEDIUM 5.4 CVE-2019-10432 Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site… Html Publisher after 1.20 Fix from $1,6002019-10-01 CRITICAL 9.9 CVE-2019-10431 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default parameter expressions in constru… Script Security after 1.64 Fix from $2,3002019-10-01 HIGH 7.5 CVE-2019-10428 Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration … Aqua Security Scanner after 3.0.17 Fix from $1,9502019-09-25 MEDIUM 5.5 CVE-2019-10429 Jenkins GitLab Logo Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users wi… Gitlab Logo after 1.0.3 Fix from $1,6002019-09-25 MEDIUM 5.5 CVE-2019-10430 Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master … Neuvector Vulnerability Scanner after 1.5 Fix from $1,6002019-09-25 MEDIUM 5.3 CVE-2019-10427 Jenkins Aqua MicroScanner Plugin 1.0.7 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form,… Aqua Microscanner after 1.0.7 Fix from $1,6002019-09-25 CRITICAL 9.9 CVE-2019-10417 Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary … Kubernetes Pipeline after 1.6 Fix from $2,3002019-09-25 CRITICAL 9.9 CVE-2019-10418 Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin provides a custom whitelist for script security that allowed attackers to invoke arbitrary … Kubernetes Pipeline after 1.6 Fix from $2,3002019-09-25 HIGH 7.5 CVE-2019-10411 Jenkins Inedo BuildMaster Plugin 2.4.0 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form,… Inedo Buildmaster after 2.4.0 Fix from $1,9502019-09-25 HIGH 7.5 CVE-2019-10412 Jenkins Inedo ProGet Plugin 1.2 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potent… Inedo Proget after 1.2 Fix from $1,9502019-09-25 MEDIUM 6.5 CVE-2019-10413 Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be v… Data Theorem Mobile App Security after 1.3 Fix from $1,6002019-09-25 MEDIUM 6.5 CVE-2019-10414 Jenkins Git Changelog Plugin 2.17 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed… Git Changelog after 2.17 Fix from $1,6002019-09-25 MEDIUM 6.5 CVE-2019-10415 Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master wh… Violation Comments To Gitlab after 2.28 Fix from $1,6002019-09-25 MEDIUM 6.5 CVE-2019-10416 Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they … Violation Comments To Gitlab after 2.28 Fix from $1,6002019-09-25 MEDIUM 6.5 CVE-2019-10422 Jenkins Call Remote Job Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ex… Call Remote Job after 1.0.21 Fix from $1,6002019-09-25 MEDIUM 6.5 CVE-2019-10425 Jenkins Google Calendar Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ex… Google Calendar after 0.4 Fix from $1,6002019-09-25