Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2018-1000012 Jenkins Warnings Plugin 4.64 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with use… Warnings after 4.64 Fix from $1,9502018-01-23 HIGH 8.8 CVE-2018-1000013 Jenkins Release Plugin 2.9 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vulnerability allowing attacker… Release after 2.9 Fix from $1,9502018-01-23 HIGH 8.8 CVE-2018-1000014 Jenkins Translation Assistance Plugin 1.15 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vulnerability a… Translation Assistance after 1.15 Fix from $1,9502018-01-23 CRITICAL 9.8 CVE-2017-1000245 The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH ke… Ssh after 2.4 Fix from $2,3002017-11-01 HIGH 8.8 CVE-2017-1000244 Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification Favorite after 2.2.0 Fix from $1,9502017-11-01 HIGH 8.8 CVE-2017-1000107 Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations,… Script Security Mitigation only Fix from $1,9502017-10-05 HIGH 8.5 CVE-2017-1000106 Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing … Blue Ocean after 1.1.5 Fix from $1,9502017-10-05 HIGH 7.5 CVE-2017-1000108 The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has bee… Pipeline Input Step Mitigation only Fix from $1,9502017-10-05 MEDIUM 6.5 CVE-2017-1000104 The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overal… Config File Provider after 2.16.1 Fix from $1,6002017-10-05 MEDIUM 6.1 CVE-2017-1000109 The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vuln… Owasp Dependency Check Mitigation only Fix from $1,6002017-10-05 MEDIUM 5.5 CVE-2017-1000113 The Deploy to container Plugin stored passwords unencrypted as part of its configuration. This allowed users with Jenkins master local file system ac… Deploy after 1.12 Fix from $1,6002017-10-05 MEDIUM 5.4 CVE-2017-1000102 The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users a… Static Analysis Utilities after 1.91 Fix from $1,6002017-10-05 MEDIUM 5.4 CVE-2017-1000103 The custom Details view of the Static Analysis Utilities based DRY Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Maliciou… Dry after 2.48 Fix from $1,6002017-10-05 MEDIUM 5.3 CVE-2017-1000105 The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing acc… Blue Ocean after 1.1.5 Fix from $1,6002017-10-05 HIGH 8.8 CVE-2017-1000090 Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery… Role Based Authorization Strategy after 2.5.0 Fix from $1,9502017-10-05 HIGH 8.8 CVE-2017-1000093 Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed at… Poll Scm after 1.3.1 Fix from $1,9502017-10-05 HIGH 8.8 CVE-2017-1000096 Arbitrary code execution due to incomplete sandbox protection: Constructors, instance variable initializers, and instance initializers in Pipeline sc… Pipeline\ after 2.36 Fix from $1,9502017-10-05 HIGH 8.0 CVE-2017-1000086 The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups,… Periodic Backup Mitigation only Fix from $1,9502017-10-05 HIGH 7.5 CVE-2017-1000092 Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at … Git Mitigation only Fix from $1,9502017-10-05 MEDIUM 6.5 CVE-2017-1000084 Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was run… Parameterized Trigger Mitigation only Fix from $1,6002017-10-05 MEDIUM 6.5 CVE-2017-1000085 Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality… Subversion after 2.8 Fix from $1,6002017-10-05 MEDIUM 6.5 CVE-2017-1000094 Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use to authentic… Docker Commons after 1.9 Fix from $1,6002017-10-05 MEDIUM 6.5 CVE-2017-1000095 The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, S… Script Security Mitigation only Fix from $1,6002017-10-05 MEDIUM 6.3 CVE-2017-1000091 GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to v… Github Branch Source Mitigation only Fix from $1,6002017-10-05 MEDIUM 5.4 CVE-2017-1000088 The Sidebar Link plugin allows users able to configure jobs, views, and agents to add entries to the sidebar of these objects. There was no input val… Sidebar Link after 1.8 Fix from $1,6002017-10-05 MEDIUM 5.3 CVE-2017-1000089 Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. … Pipeline\ after 2.5 Fix from $1,6002017-10-05 MEDIUM 5.3 CVE-2014-9634 Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers t… Jenkins after 1.585 Fix from $1,6002017-09-12 MEDIUM 5.3 CVE-2014-9635 Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it eas… Jenkins after 1.585 Fix from $1,6002017-09-12 CRITICAL 9.8 CVE-2017-1000362 The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup direct… Jenkins after 1.498 Fix from $2,3002017-07-17 HIGH 7.5 CVE-2016-4986 Directory traversal vulnerability in the TAP plugin before 1.25 in Jenkins allows remote attackers to read arbitrary files via an unspecified paramet… Tap 1.25+ Fix from $1,9502017-02-09