Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2019-10375 An arbitrary file read vulnerability in Jenkins File System SCM Plugin 2.1 and earlier allows attackers able to configure jobs in Jenkins to obtain t… File System Scm after 2.1 Fix from $1,6002019-08-07 MEDIUM 6.1 CVE-2019-10372 An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users… Gitlab Oauth after 1.4 Fix from $1,6002019-08-07 MEDIUM 6.1 CVE-2019-10376 A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inject arbitrary HTML and JavaSc… Wall Display after 0.6.34 Fix from $1,6002019-08-07 MEDIUM 5.5 CVE-2019-10367 Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expec… Configuration As Code after 1.26 Fix from $1,6002019-08-07 MEDIUM 5.4 CVE-2019-10373 A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to edit the build pipeline descr… Build Pipeline after 1.5.8 Fix from $1,6002019-08-07 MEDIUM 5.4 CVE-2019-10374 A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to edit descriptions and other … Pegdown Formatter after 1.3 Fix from $1,6002019-08-07 MEDIUM 6.5 CVE-2019-10366 Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be view… Skytap Cloud Ci after 2.06 Fix from $1,6002019-07-31 HIGH 8.8 CVE-2019-10355 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute … Script Security after 1.61 Fix from $1,9502019-07-31 HIGH 8.8 CVE-2019-10356 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method pointer expressions allowed attac… Script Security after 1.61 Fix from $1,9502019-07-31 MEDIUM 6.5 CVE-2019-10358 Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing sensitive build variables… Maven after 3.3 Fix from $1,6002019-07-31 MEDIUM 6.3 CVE-2019-10359 A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doSubmit method allowed attacker… M2release after 0.14.0 Fix from $1,6002019-07-31 MEDIUM 5.5 CVE-2019-10345 Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export. Configuration As Code 1.20+ Fix from $1,6002019-07-31 MEDIUM 5.5 CVE-2019-10361 Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access … M2release after 0.14.0 Fix from $1,6002019-07-31 MEDIUM 5.5 CVE-2019-10364 Jenkins Amazon EC2 Plugin 1.43 and earlier wrote the beginning of private keys to the Jenkins system log. Ec2 after 1.43 Fix from $1,6002019-07-31 MEDIUM 5.4 CVE-2019-10360 A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScr… M2 Release after 0.14.0 Fix from $1,6002019-07-31 MEDIUM 5.4 CVE-2019-10362 Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during configuration import when expo… Configuration As Code after 1.24 Fix from $1,6002019-07-31 MEDIUM 6.5 CVE-2019-1010241 Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated user… Credentials Binding No fix yet Fix from $1,6002019-07-19 HIGH 7.5 CVE-2019-10353 CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF prote… Jenkins after 2.185 Fix from $1,9502019-07-17 MEDIUM 6.5 CVE-2019-10352EPSS 10% A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allow… Jenkins after 2.185 Fix from $1,6002019-07-17 HIGH 8.8 CVE-2019-10350 Jenkins Port Allocator Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Ext… Port Allocator after 1.8 Fix from $1,9502019-07-11 HIGH 8.8 CVE-2019-10351 Jenkins Caliper CI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extende… Caliper Ci after 2.3 Fix from $1,9502019-07-11 HIGH 8.8 CVE-2019-10340 A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with… Docker after 1.1.6 Fix from $1,9502019-07-11 HIGH 8.8 CVE-2019-10347 Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users with access to the master file … Mashup Portlets after 1.0.9 Fix from $1,9502019-07-11 HIGH 8.8 CVE-2019-10348 Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read… Gogs after 1.0.14 Fix from $1,9502019-07-11 MEDIUM 6.5 CVE-2019-10341 A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with Overall/Read ac… Docker after 1.1.6 Fix from $1,6002019-07-11 MEDIUM 6.1 CVE-2019-10346 A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML an… Embeddable Build Status after 2.0.1 Fix from $1,6002019-07-11 MEDIUM 5.4 CVE-2019-10349 A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Je… Dependency Graph Viewer after 0.13 Fix from $1,6002019-07-11 HIGH 8.8 CVE-2019-10338 A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed at… Jx Resources after 1.0.36 Fix from $1,9502019-06-11 HIGH 8.8 CVE-2019-10339 A missing permission check in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed users with Overall… Jx Resources after 1.0.36 Fix from $1,9502019-06-11 HIGH 7.5 CVE-2019-10337 An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the inp… Token Macro after 2.7 Fix from $1,9502019-06-11