Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2019-10336 A reflected cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.6 and earlier allowed attackers able to control the output of the E… Electricflow after 1.1.6 Fix from $1,6002019-06-11 MEDIUM 6.5 CVE-2019-10334 Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM when MultipartUtility.ja… Electricflow after 1.1.5 Fix from $1,6002019-06-11 MEDIUM 5.4 CVE-2019-10335 A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to configure jobs in Jenkins or c… Electricflow after 1.1.6 Fix from $1,6002019-06-11 CRITICAL 9.9 CVE-2019-10328 Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitrary meth… Pipeline Remote Loader after 1.4 Fix from $2,3002019-05-31 HIGH 8.1 CVE-2019-10327 An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a tempo… Pipeline Maven Integration after 1.7.0 Fix from $1,9502019-05-31 MEDIUM 5.4 CVE-2019-10325 A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitra… Warnings Next Generation after 5.0.0 Fix from $1,6002019-05-31 CRITICAL 9.3 CVE-2019-10309 Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity p… Self Organizing Swarm Modules Mitigation only Fix from $2,3002019-04-30 HIGH 8.8 CVE-2019-10310 A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doT… Ansible Tower after 0.9.1 Fix from $1,9502019-04-30 HIGH 8.8 CVE-2019-10311 A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationDescriptor#doTestTowerConnecti… Ansible Tower after 0.9.1 Fix from $1,9502019-04-30 HIGH 8.8 CVE-2019-10313 Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with a… Twitter after 0.7 Fix from $1,9502019-04-30 HIGH 8.8 CVE-2019-10315 Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent CSRF. Github Authentication after 0.31 Fix from $1,9502019-04-30 HIGH 8.8 CVE-2019-10316 Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they c… Aqua Microscanner after 1.0.5 Fix from $1,9502019-04-30 HIGH 8.8 CVE-2019-10318 Jenkins Azure AD Plugin 0.3.3 and earlier stored the client secret unencrypted in the global config.xml configuration file on the Jenkins master wher… Azure Ad after 0.3.3 Fix from $1,9502019-04-30 MEDIUM 6.5 CVE-2019-10307 A cross-site request forgery vulnerability in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave f… Static Analysis Utilities after 1.95 Fix from $1,6002019-04-30 MEDIUM 6.5 CVE-2019-10308 A missing permission check in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave form handler meth… Static Analysis Utilities after 1.95 Fix from $1,6002019-04-30 MEDIUM 5.9 CVE-2019-10314 Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM. Koji after 0.3 Fix from $1,6002019-04-30 MEDIUM 5.9 CVE-2019-10317 Jenkins SiteMonitor Plugin 0.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM. Sitemonitor after 0.5 Fix from $1,6002019-04-30 CRITICAL 9.9 CVE-2019-10306 A sandbox bypass vulnerability in Jenkins ontrack Plugin 3.4 and earlier allowed attackers with control over ontrack DSL definitions to execute arbit… Ontrack after 3.4 Fix from $2,3002019-04-18 HIGH 8.8 CVE-2019-10301 A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation method allowed … GitLab after 1.5.11 Fix from $1,9502019-04-18 HIGH 8.8 CVE-2019-10302 Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be vie… Jira Ext after 0.8 Fix from $1,9502019-04-18 HIGH 8.8 CVE-2019-10303 Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master w… Azure Publishersettings Credentials after 1.2 Fix from $1,9502019-04-18 HIGH 8.0 CVE-2019-10300 A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection form validation… GitLab after 1.5.11 Fix from $1,9502019-04-18 MEDIUM 6.5 CVE-2019-10304 A cross-site request forgery vulnerability in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method … Xebialabs Xl Deploy after 7.5.3 Fix from $1,6002019-04-18 MEDIUM 6.5 CVE-2019-10305 A missing permission check in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form validation method allows attackers… Xebialabs Xl Deploy after 7.5.3 Fix from $1,6002019-04-18 HIGH 8.1 CVE-2019-1003049 Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins … Jenkins after 2.171 Fix from $1,9502019-04-10 MEDIUM 5.4 CVE-2019-1003050 The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlie… Jenkins after 2.171 Fix from $1,6002019-04-10 HIGH 8.8 CVE-2019-10294 Jenkins Kmap Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read… Kmap Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10295 Jenkins crittercism-dsym Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with E… Crittercism Dsym Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10296 Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by us… Serena Sra Deploy Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-10297 Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with … Sametime Mitigation only Fix from $1,9502019-04-04