Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2018-6356 Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing… Jenkins 2.89.4 / 2.107+ Fix from $1,6002018-02-20 MEDIUM 5.3 CVE-2018-1000067 An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jen… Jenkins after 2.106 Fix from $1,6002018-02-16 MEDIUM 5.3 CVE-2018-1000068 An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to acces… Jenkins after 2.106 Fix from $1,6002018-02-16 HIGH 8.8 CVE-2018-1000058 Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to J… Pipeline Supporting Apis after 2.17 Fix from $1,9502018-02-09 HIGH 8.3 CVE-2018-1000056 Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user p… Junit after 1.23 Fix from $1,9502018-02-09 HIGH 8.3 CVE-2018-1000054 Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user perm… Ccm after 3.1 Fix from $1,9502018-02-09 HIGH 8.3 CVE-2018-1000055 Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with … Android Lint after 2.5 Fix from $1,9502018-02-09 CRITICAL 9.8 CVE-2017-1000353 KEVEPSS 100% Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated re… Jenkins after 2.56 Fix from $2,3002018-01-29 HIGH 8.8 CVE-2017-1000354 Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to a login command which allowed impersonating any Jenkins user. T… Jenkins after 2.56 Fix from $1,9502018-01-29 HIGH 8.8 CVE-2017-1000356EPSS 7% Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an issue in the Jenkins user database authentication realm: cre… Jenkins after 2.56 Fix from $1,9502018-01-29 MEDIUM 6.5 CVE-2017-1000355 Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void. Jenkins after 2.56 Fix from $1,6002018-01-29 HIGH 8.8 CVE-2017-1000403 Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effecti… Speaks\! after 0.1.1 Fix from $1,9502018-01-26 MEDIUM 6.1 CVE-2017-1000404 The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resu… Delivery Pipeline after 1.0.7 Fix from $1,6002018-01-26 MEDIUM 5.9 CVE-2017-1000402 Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly… Swarm after 3.4 Fix from $1,6002018-01-26 HIGH 8.8 CVE-2017-1000393 Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could configure a launch method called 'L… Jenkins after 2.83 Fix from $1,9502018-01-26 HIGH 7.8 CVE-2017-1000387 Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.Buil… Build Publisher after 1.21 Fix from $1,9502018-01-26 HIGH 7.5 CVE-2017-1000394 Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CV… Jenkins after 2.83 Fix from $1,9502018-01-26 HIGH 7.3 CVE-2017-1000391 Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual user accounts, as well as user… Jenkins after 2.88 Fix from $1,9502018-01-26 MEDIUM 6.1 CVE-2017-1000389 Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These res… Global Build Stats after 1.4 Fix from $1,6002018-01-26 MEDIUM 5.9 CVE-2017-1000396 Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectl… Jenkins after 2.83 Fix from $1,6002018-01-26 MEDIUM 5.9 CVE-2017-1000397 Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verif… Maven after 2.17 Fix from $1,6002018-01-26 MEDIUM 5.4 CVE-2017-1000386 Jenkins Active Choices plugin version 1.5.3 and earlier allowed users with Job/Configure permission to provide arbitrary HTML to be shown on the 'Bui… Active Choices after 1.5.2 Fix from $1,6002018-01-26 MEDIUM 6.5 CVE-2017-1000505 In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coerc… Script Security after 1.36 Fix from $1,6002018-01-25 HIGH 8.8 CVE-2017-1000502 Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the m… Ec2 after 1.37 Fix from $1,9502018-01-24 HIGH 8.1 CVE-2017-1000503 A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of execution of commands during initial… Jenkins after 2.94 Fix from $1,9502018-01-24 HIGH 8.1 CVE-2017-1000504 A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initiali… Jenkins after 2.94 Fix from $1,9502018-01-24 HIGH 8.8 CVE-2018-1000008 Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user per… Pmd after 3.49 Fix from $1,9502018-01-23 HIGH 8.8 CVE-2018-1000009 Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with u… Checkstyle after 3.49 Fix from $1,9502018-01-23 HIGH 8.8 CVE-2018-1000010 Jenkins DRY Plugin 2.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user per… Dry after 2.49 Fix from $1,9502018-01-23 HIGH 8.8 CVE-2018-1000011 Jenkins FindBugs Plugin 4.71 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with use… Findbugs after 4.71 Fix from $1,9502018-01-23