Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2017-2608EPSS 6% Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserialization of various types in javax.i… Jenkins 2.32.2+ Fix from $1,9502018-05-15 MEDIUM 5.4 CVE-2017-2612 In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds… Jenkins 2.32.2 / 2.44+ Fix from $1,6002018-05-15 MEDIUM 5.4 CVE-2017-2601 Jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in parameter names and descriptions (SECURITY-353). Users with… Jenkins 2.32.2 / 2.44+ Fix from $1,6002018-05-10 MEDIUM 6.5 CVE-2018-1000175 A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to confi… Html Publisher after 1.15 Fix from $1,6002018-05-08 MEDIUM 6.5 CVE-2018-1000176 An exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/email… Email Extension after 2.61 Fix from $1,6002018-05-08 MEDIUM 6.1 CVE-2018-1000174 An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirec… Google Login after 1.3 Fix from $1,6002018-05-08 MEDIUM 5.9 CVE-2018-1000173 A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized atta… Google Login after 1.3 Fix from $1,6002018-05-08 MEDIUM 5.4 CVE-2018-1000177 A cross-site scripting vulnerability exists in Jenkins S3 Plugin 0.10.12 and older in src/main/resources/hudson/plugins/s3/S3ArtifactsProjectAction/j… S3 Publisher after 0.10.12 Fix from $1,6002018-05-08 MEDIUM 5.4 CVE-2018-1000170 A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that al… Jenkins after 2.107.1 Fix from $1,6002018-04-16 MEDIUM 5.3 CVE-2018-1000169 An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler… Jenkins after 2.107.1 Fix from $1,6002018-04-16 MEDIUM 5.4 CVE-2017-2599 Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.… Jenkins 2.32.2 / 2.44+ Fix from $1,6002018-04-11 HIGH 8.8 CVE-2018-1000146 An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to config… Liquibase Runner after 1.3.0 Fix from $1,9502018-04-05 HIGH 8.8 CVE-2018-1000153 A cross-site request forgery vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTempl… Vsphere after 2.16 Fix from $1,9502018-04-05 HIGH 7.8 CVE-2018-1000142 An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java t… Github Pull Request Builder after 1.39.0 Fix from $1,9502018-04-05 MEDIUM 6.7 CVE-2018-1000143 An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java t… Github Pull Request Builder after 1.39.0 Fix from $1,6002018-04-05 MEDIUM 6.5 CVE-2018-1000145 An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that … Perforce after 1.3.36 Fix from $1,6002018-04-05 MEDIUM 6.5 CVE-2018-1000148 An exposure of sensitive information vulnerability exists in Jenkins Copy To Slave Plugin version 1.4.4 and older in CopyToSlaveBuildWrapper.java tha… Copy To Slave after 1.4.4 Fix from $1,6002018-04-05 MEDIUM 6.3 CVE-2018-1000152 An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate… Vsphere after 2.16 Fix from $1,6002018-04-05 MEDIUM 6.1 CVE-2018-1000144 A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in CukedoctorBaseAction#doDynamic that d… Cucumber Living Documentation after 1.0.12 Fix from $1,6002018-04-05 MEDIUM 5.6 CVE-2018-1000149 A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, … Ansible after 0.8 Fix from $1,6002018-04-05 MEDIUM 5.6 CVE-2018-1000151 A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by def… Vsphere after 2.16 Fix from $1,6002018-04-05 HIGH 8.0 CVE-2018-8718EPSS 7% Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized ma… Mailer after 1.20 Fix from $1,9502018-03-27 HIGH 7.8 CVE-2018-1000104 A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with… Coverity after 1.10.0 Fix from $1,9502018-03-13 MEDIUM 6.5 CVE-2018-1000107 An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobP… Job And Node Ownership after 0.11.0 Fix from $1,6002018-03-13 MEDIUM 6.1 CVE-2018-1000108 A cross-site scripting vulnerability exists in Jenkins CppNCSS Plugin 1.1 and earlier in AbstractProjectAction/index.jelly that allow an attacker to … Cppncss after 1.1 Fix from $1,6002018-03-13 MEDIUM 5.4 CVE-2018-1000106 An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and P… Gerrit Trigger after 2.27.4 Fix from $1,6002018-03-13 MEDIUM 5.4 CVE-2018-1000113 A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and earlier in TestLinkBuildAction/summary.jelly and others that allow an… Testlink after 3.12 Fix from $1,6002018-03-13 MEDIUM 5.3 CVE-2018-1000110 An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network… Git after 3.7.0 Fix from $1,6002018-03-13 MEDIUM 5.3 CVE-2018-1000111 An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionReposit… Subversion after 2.10.2 Fix from $1,6002018-03-13 MEDIUM 5.3 CVE-2018-1000112 An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker wi… Mercurial after 2.2 Fix from $1,6002018-03-13