Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2018-1000866 A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxT… Pipeline\ after 2.59 Fix from $1,9502018-12-10 HIGH 8.2 CVE-2018-1000863EPSS 7% A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to… Jenkins after 2.153 Fix from $1,9502018-12-10 MEDIUM 6.5 CVE-2018-1000864 A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Rea… Jenkins after 2.153 Fix from $1,6002018-12-10 MEDIUM 6.5 CVE-2018-1999047 A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel … Jenkins after 2.137 Fix from $1,6002018-08-23 HIGH 7.5 CVE-2018-1999043 A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuth… Jenkins after 2.137 Fix from $1,9502018-08-23 MEDIUM 6.5 CVE-2018-1999044 A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in CronTab.java that allows attackers with Overall/Read pe… Jenkins after 2.137 Fix from $1,6002018-08-23 MEDIUM 5.4 CVE-2018-1999045 A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2… Jenkins after 2.137 Fix from $1,6002018-08-23 MEDIUM 5.3 CVE-2018-1999042 A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name… Jenkins after 2.137 Fix from $1,6002018-08-23 MEDIUM 5.3 CVE-2017-2654 jenkins-email-ext before version 2.57.1 is vulnerable to an Information Exposure. The Email Extension Plugins is able to send emails to a dynamically… Email Extension 2.57.1+ Fix from $1,6002018-08-06 HIGH 8.8 CVE-2018-1999040 An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attacke… Kubernetes after 1.10.1 Fix from $1,9502018-08-01 MEDIUM 5.5 CVE-2018-1999041 An exposure of sensitive information vulnerability exists in Jenkins Tinfoil Security Plugin 1.6.1 and earlier in TinfoilScanRecorder.java that allow… Tinfoil Security after 1.6.1 Fix from $1,6002018-08-01 HIGH 8.8 CVE-2018-1999028 An exposure of sensitive information vulnerability exists in Jenkins Accurev Plugin 0.7.16 and earlier in AccurevSCM.java that allows attackers to ca… Accurev after 0.7.16 Fix from $1,9502018-08-01 HIGH 7.5 CVE-2018-1999027 An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that… Saltstack after 3.1.6 Fix from $1,9502018-08-01 HIGH 7.4 CVE-2018-1999025 A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows a… Tracetronic Ecu Test after 2.3 Fix from $1,9502018-08-01 HIGH 7.4 CVE-2018-1999034 A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.jav… Inedo Proget after 0.8 Fix from $1,9502018-08-01 HIGH 7.4 CVE-2018-1999035 A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java… Inedo Buildmaster after 1.3 Fix from $1,9502018-08-01 MEDIUM 6.5 CVE-2018-1999026 A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers … Tracetronic Ecu Test after 2.3 Fix from $1,6002018-08-01 MEDIUM 6.5 CVE-2018-1999031 An exposure of sensitive information vulnerability exists in Jenkins meliora-testlab Plugin 1.14 and earlier in TestlabNotifier.java that allows atta… Meliora Testlab after 1.14 Fix from $1,6002018-08-01 MEDIUM 6.5 CVE-2018-1999036 An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the… Ssh Agent after 1.15 Fix from $1,6002018-08-01 MEDIUM 5.4 CVE-2018-1999029 A cross-site scripting vulnerability exists in Jenkins Shelve Project Plugin 1.5 and earlier in ShelveProjectAction/index.jelly, ShelvedProjectsActio… Shelve Project after 1.5 Fix from $1,6002018-08-01 MEDIUM 5.4 CVE-2018-1999030 An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and earlier in Artifactor… Maven Artifact Choicelistprovider \(nexus\) after 1.3.1 Fix from $1,6002018-08-01 HIGH 8.8 CVE-2017-2652 It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the d… Distributed Fork after 1.5.0 Fix from $1,9502018-07-27 HIGH 8.5 CVE-2017-2650 It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access… Pipeline Classpath Step Mitigation only Fix from $1,9502018-07-27 HIGH 8.1 CVE-2017-2649 It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server,… Active Directory after 2.2 Fix from $1,9502018-07-27 MEDIUM 5.6 CVE-2017-2648 It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks. Ssh Slaves 1.15+ Fix from $1,6002018-07-27 HIGH 8.8 CVE-2018-1999001EPSS 18% A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attacker… Jenkins after 2.132 Fix from $1,9502018-07-23 HIGH 7.5 CVE-2018-1999002EPSS 87% A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapl… Jenkins after 2.132 Fix from $1,9502018-07-23 MEDIUM 5.4 CVE-2018-1999005 A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/contro… Jenkins after 2.132 Fix from $1,6002018-07-23 MEDIUM 5.4 CVE-2018-1999007 A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stap… Jenkins after 2.132 Fix from $1,6002018-07-23 HIGH 7.8 CVE-2018-1000401 Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipe… Aws Codepipeline after 0.36 Fix from $1,9502018-07-09