Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2018-1000403 Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeploy… Aws Codedeploy after 1.19 Fix from $1,9502018-07-09 HIGH 7.8 CVE-2018-1000404 Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFacto… Aws Codebuild after 0.26 Fix from $1,9502018-07-09 HIGH 8.8 CVE-2018-1000600EPSS 91% A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allow… GitHub after 1.29.1 Fix from $1,9502018-06-26 HIGH 8.8 CVE-2018-1000603 A exposure of sensitive information vulnerability exists in Jenkins Openstack Cloud Plugin 2.35 and earlier in BootSource.java, InstancesToRun.java, … Openstack Cloud after 2.35 Fix from $1,9502018-06-26 HIGH 8.8 CVE-2018-1000610 A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java,… Configuration As Code Mitigation only Fix from $1,9502018-06-26 HIGH 7.4 CVE-2018-1000605 A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidat… Collabnet after 2.0.4 Fix from $1,9502018-06-26 HIGH 7.2 CVE-2018-1000608 A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker… Z\/os Connector after 1.2.6.1 Fix from $1,9502018-06-26 MEDIUM 6.5 CVE-2018-1000601 A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers wi… Ssh Credentials after 1.13 Fix from $1,6002018-06-26 MEDIUM 6.5 CVE-2018-1000606 A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overal… Urltrigger after 0.41 Fix from $1,6002018-06-26 MEDIUM 6.5 CVE-2018-1000607 A arbitrary file write vulnerability exists in Jenkins Fortify CloudScan Plugin 1.5.1 and earlier in ArchiveUtil.java that allows attackers able to c… Fortify Cloudscan after 1.5.1 Fix from $1,6002018-06-26 MEDIUM 6.5 CVE-2018-1000609 A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java th… Configuration As Code Mitigation only Fix from $1,6002018-06-26 MEDIUM 5.9 CVE-2018-1000602 A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impe… Saml after 1.0.6 Fix from $1,6002018-06-26 MEDIUM 5.4 CVE-2018-1000604 A persisted cross-site scripting vulnerability exists in Jenkins Badge Plugin 1.4 and earlier in BadgeSummaryAction.java, HtmlBadgeAction.java that a… Badge after 1.4 Fix from $1,6002018-06-26 HIGH 8.1 CVE-2018-1000194 A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicio… Jenkins after 2.120 Fix from $1,9502018-06-05 HIGH 8.1 CVE-2018-1000197 An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users wit… Black Duck Hub after 3.0.3 Fix from $1,9502018-06-05 MEDIUM 6.5 CVE-2018-1000196 A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifier.rb, views/gitlab_notifier/g… Gitlab Hook after 1.4.2 Fix from $1,6002018-06-05 MEDIUM 6.5 CVE-2018-1000198 A XML external entity processing vulnerability exists in Jenkins Black Duck Hub Plugin 3.1.0 and older in PostBuildScanDescriptor.java that allows at… Black Duck Hub after 3.1.0 Fix from $1,6002018-06-05 MEDIUM 5.4 CVE-2018-1000202 A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers… Groovy Postbuild after 2.3.1 Fix from $1,6002018-06-05 HIGH 8.8 CVE-2018-1000189 A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allows attackers with Overall/Rea… Absint Astree after 1.0.5 Fix from $1,9502018-06-05 MEDIUM 6.5 CVE-2018-1000183 A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers w… GitHub after 1.29.0 Fix from $1,6002018-06-05 MEDIUM 6.5 CVE-2018-1000186 A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that … Github Pull Request Builder after 1.41.0 Fix from $1,6002018-06-05 MEDIUM 6.5 CVE-2018-1000187 A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in … Kubernetes after 1.7.0 Fix from $1,6002018-06-05 MEDIUM 6.5 CVE-2018-1000190 A exposure of sensitive information vulnerability exists in Jenkins Black Duck Hub Plugin 4.0.0 and older in PostBuildScanDescriptor.java that allows… Black Duck Hub after 4.0.0 Fix from $1,6002018-06-05 MEDIUM 6.5 CVE-2018-1000191 A exposure of sensitive information vulnerability exists in Jenkins Black Duck Detect Plugin 1.4.0 and older in DetectPostBuildStepDescriptor.java th… Synopsys Detect after 1.4.0 Fix from $1,6002018-06-05 MEDIUM 6.4 CVE-2018-1000182 A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.… Git after 3.9.0 Fix from $1,6002018-06-05 MEDIUM 5.4 CVE-2018-1000184 A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Ov… GitHub after 1.29.0 Fix from $1,6002018-06-05 MEDIUM 5.4 CVE-2018-1000188 A server-side request forgery vulnerability exists in Jenkins CAS Plugin 1.4.1 and older in CasSecurityRealm.java that allows attackers with Overall/… Cas after 1.4.1 Fix from $1,6002018-06-05 MEDIUM 5.4 CVE-2017-2607 jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting vulnerability in console notes (SECURITY-382). Jenkins allows … Jenkins 2.32.2 / 2.44+ Fix from $1,6002018-05-21 MEDIUM 5.4 CVE-2017-2613 jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record was only retained until restar… Jenkins 2.32.2 / 2.44+ Fix from $1,6002018-05-15 MEDIUM 5.4 CVE-2017-2610 jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in search suggestions due to improperly escaping users with le… Jenkins 2.32.2 / 2.44+ Fix from $1,6002018-05-15