Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2019-10419 Jenkins vFabric Application Director Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be v… Vfabric Application Director after 1.3 Fix from $1,6002019-09-25 MEDIUM 5.5 CVE-2019-10420 Jenkins Assembla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with … Assembla after 1.4 Fix from $1,6002019-09-25 MEDIUM 5.5 CVE-2019-10423 Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with … Codescan after 0.11 Fix from $1,6002019-09-25 MEDIUM 5.5 CVE-2019-10424 Jenkins elOyente Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with … Eloyente after 1.3 Fix from $1,6002019-09-25 MEDIUM 5.5 CVE-2019-10426 Jenkins Gem Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users … Gem Publisher after 1.0 Fix from $1,6002019-09-25 MEDIUM 5.4 CVE-2019-10410 Jenkins Log Parser Plugin 2.0 and earlier did not escape an error message, resulting in a cross-site scripting vulnerability exploitable by users abl… Log Parser after 2.0 Fix from $1,6002019-09-25 MEDIUM 6.5 CVE-2019-10407 Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passed to a build without masking sensitive variables … Project Inheritance after 2.0.0 Fix from $1,6002019-09-25 MEDIUM 5.4 CVE-2019-10401 In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as HTML when expanded, resulting … Jenkins after 2.196 Fix from $1,6002019-09-25 MEDIUM 5.4 CVE-2019-10402 In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:combobox form control interpreted its item labels as HTML, resulting in a stored XSS vul… Jenkins after 2.196 Fix from $1,6002019-09-25 MEDIUM 5.4 CVE-2019-10403 Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vuln… Jenkins after 2.196 Fix from $1,6002019-09-25 MEDIUM 5.4 CVE-2019-10404 Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the reason why a queue items is blcoked in tooltips, resulting in a stored XSS vuln… Jenkins after 2.196 Fix from $1,6002019-09-25 MEDIUM 5.4 CVE-2019-10405EPSS 66% Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers expl… Jenkins after 2.196 Fix from $1,6002019-09-25 HIGH 8.8 CVE-2019-10392EPSS 26% Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote',… Git Client after 2.8.4 Fix from $1,9502019-09-12 MEDIUM 5.5 CVE-2019-10398 Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could … Beaker Builder after 1.9 Fix from $1,6002019-09-12 MEDIUM 5.4 CVE-2019-10395 Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site scripting vulnerability in Je… Build Environment after 1.6 Fix from $1,6002019-09-12 MEDIUM 5.4 CVE-2019-10396 Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vulnerability exploitable by us… Dashboard View after 2.11 Fix from $1,6002019-09-12 HIGH 8.8 CVE-2019-10390 A sandbox bypass vulnerability in Jenkins Splunk Plugin 1.7.4 and earlier allowed attackers with Overall/Read permission to provide a Groovy script t… Splunk after 1.7.4 Fix from $1,9502019-08-28 MEDIUM 6.5 CVE-2019-10391 Jenkins IBM Application Security on Cloud Plugin 1.2.4 and earlier transmitted configured passwords in plain text as part of job configuration forms,… Ibm Application Security On Cloud after 1.2.4 Fix from $1,6002019-08-28 HIGH 8.8 CVE-2019-10384 Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens… Jenkins after 2.191 Fix from $1,9502019-08-28 HIGH 8.8 CVE-2019-10380 Jenkins Simple Travis Pipeline Runner Plugin 1.0 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able… Simple Travis Pipeline Runner after 1.0 Fix from $1,9502019-08-07 HIGH 8.8 CVE-2019-10386 A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows use… Xl Testview after 1.2.0 Fix from $1,9502019-08-07 HIGH 7.5 CVE-2019-10381 Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM. Codefresh Integration after 1.8 Fix from $1,9502019-08-07 MEDIUM 6.5 CVE-2019-10382 Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM. Vmware Lab Manager Slaves after 0.2.8 Fix from $1,6002019-08-07 MEDIUM 6.5 CVE-2019-10385 Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by user… Eggplant after 2.2 Fix from $1,6002019-08-07 MEDIUM 6.5 CVE-2019-10387 A missing permission check in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/… Xl Testview after 1.2.0 Fix from $1,6002019-08-07 MEDIUM 5.3 CVE-2019-10378 Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be view… Testlink after 3.16 Fix from $1,6002019-08-07 HIGH 8.8 CVE-2019-10368 A cross-site request forgery vulnerability in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JClouds… Jclouds after 2.14 Fix from $1,9502019-08-07 HIGH 7.5 CVE-2019-10371 A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to… Gitlab Oauth after 1.4 Fix from $1,9502019-08-07 MEDIUM 6.5 CVE-2019-10369 A missing permission check in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JCloudsCloud.Descriptor… Jclouds after 2.14 Fix from $1,6002019-08-07 MEDIUM 6.5 CVE-2019-10370 Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially… Mask Passwords after 2.12.0 Fix from $1,6002019-08-07