Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2019-1003060 Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by u… Official Owasp Zap Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003061 Jenkins jenkins-cloudformation-plugin Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by… Jenkins Cloudformation Plugin Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003062 Jenkins AWS CloudWatch Logs Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be … Aws Cloudwatch Logs Publisher Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003063 Jenkins Amazon SNS Build Notifier Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be view… Amazon Sns Build Notifier Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003064 Jenkins aws-device-farm Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by user… Aws Device Farm Mitigation only Fix from $1,9502019-04-04 HIGH 8.8 CVE-2019-1003065 Jenkins CloudShare Docker-Machine Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be view… Cloudshare Docker Machine Mitigation only Fix from $1,9502019-04-04 MEDIUM 6.5 CVE-2019-1003058 A cross-site request forgery vulnerability in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers to… Ftp Publisher Mitigation only Fix from $1,6002019-04-04 MEDIUM 6.5 CVE-2019-1003059 A missing permission check in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers with Overall/Read … Ftp Publisher Mitigation only Fix from $1,6002019-04-04 CRITICAL 9.8 CVE-2019-1003040 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scri… Script Security after 1.55 Fix from $2,3002019-03-28 CRITICAL 9.8 CVE-2019-1003041 A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scr… Pipeline\ after 2.64 Fix from $2,3002019-03-28 HIGH 7.8 CVE-2019-1003048 A vulnerability in Jenkins PRQA Plugin 3.1.0 and earlier allows attackers with local file system access to the Jenkins home directory to obtain the u… Prqa after 3.1.0 Fix from $1,9502019-03-28 HIGH 7.5 CVE-2019-1003043 A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read permission to connect to an attac… Slack Notification after 2.19 Fix from $1,9502019-03-28 HIGH 7.1 CVE-2019-1003044 A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified… Slack Notification after 2.19 Fix from $1,9502019-03-28 MEDIUM 6.5 CVE-2019-1003046 A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers to initiate a connection … Fortify On Demand Uploader after 3.0.10 Fix from $1,6002019-03-28 MEDIUM 6.5 CVE-2019-1003047 A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate … Fortify On Demand Uploader after 3.0.10 Fix from $1,6002019-03-28 MEDIUM 5.4 CVE-2019-1003042 A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to control resource names to inject a… Lockable Resources after 2.4 Fix from $1,6002019-03-28 CRITICAL 9.9 CVE-2019-1003029 KEVEPSS 74% A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbo… Script Security after 1.53 Fix from $2,3002019-03-08 CRITICAL 9.9 CVE-2019-1003030 KEVEPSS 97% A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cp… Pipeline\ after 2.63 Fix from $2,3002019-03-08 CRITICAL 9.9 CVE-2019-1003031 A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java tha… Matrix Project after 1.13 Fix from $2,3002019-03-08 CRITICAL 9.9 CVE-2019-1003032 A sandbox bypass vulnerability exists in Jenkins Email Extension Plugin 2.64 and earlier in pom.xml, src/main/java/hudson/plugins/emailext/ExtendedEm… Email Extension after 2.64 Fix from $2,3002019-03-08 CRITICAL 9.9 CVE-2019-1003034 A sandbox bypass vulnerability exists in Jenkins Job DSL Plugin 1.71 and earlier in job-dsl-core/src/main/groovy/javaposse/jobdsl/dsl/AbstractDslScri… Job Dsl after 1.71 Fix from $2,3002019-03-08 HIGH 8.8 CVE-2019-1003033 A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.1 and earlier in pom.xml, src/main/java/hudson/plugins/groovy/StringScriptSource.jav… Groovy after 2.1 Fix from $1,9502019-03-08 HIGH 8.8 CVE-2019-1003039 An insufficiently protected credentials vulnerability exists in JenkinsAppDynamics Dashboard Plugin 1.0.14 and earlier in src/main/java/nl/codecentri… Appdynamics after 1.0.14 Fix from $1,9502019-03-08 HIGH 7.8 CVE-2019-1003038 An insufficiently protected credentials vulnerability exists in Jenkins Repository Connector Plugin 1.2.4 and earlier in src/main/java/org/jvnet/huds… Repository Connector after 1.2.4 Fix from $1,9502019-03-08 MEDIUM 6.5 CVE-2019-1003037 An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVM… Azure Vm Agents after 0.8.0 Fix from $1,6002019-03-08 HIGH 8.8 CVE-2019-1003024 A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectASTTransformsCustomizer.java that allows attackers … Script Security after 1.52 Fix from $1,9502019-02-20 HIGH 8.8 CVE-2019-1003025 A exposure of sensitive information vulnerability exists in Jenkins Cloud Foundry Plugin 2.3.1 and earlier in AbstractCloudFoundryPushDescriptor.java… Cloud Foundry after 2.3.1 Fix from $1,9502019-02-20 MEDIUM 6.5 CVE-2019-1003022 A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads run… Monitoring after 1.74.0 Fix from $1,6002019-02-06 MEDIUM 6.1 CVE-2019-1003023 A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/java/io/jenkins/plugins/analysis… Warnings Next Generation after 1.0.1 Fix from $1,6002019-02-06 CRITICAL 9.1 CVE-2019-1003015 An XML external entity processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport… Job Import after 2.1 Fix from $2,3002019-02-06