Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-32997 Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login. Cas after 1.6.2 Fix from $1,9502023-05-16 HIGH 8.8 CVE-2023-32998 A cross-site request forgery (CSRF) vulnerability in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers to connect to an attacker-specified… Appspider after 1.0.15 Fix from $1,9502023-05-16 HIGH 7.5 CVE-2023-33000 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasin… Ns Nd Integration Performance Publisher after 4.8.0.149 Fix from $1,9502023-05-16 HIGH 7.5 CVE-2023-33001 Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when… Hashicorp Vault after 360.v0a_1c04cf807d Fix from $1,9502023-05-16 MEDIUM 5.4 CVE-2023-33002 Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stored cross-site scripting (XSS)… Testcomplete Support after 2.8.1 Fix from $1,6002023-05-16 MEDIUM 5.4 CVE-2023-33005 Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login. Wso2 Oauth after 1.0 Fix from $1,6002023-05-16 MEDIUM 5.4 CVE-2023-33006 A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick users into logging in to the… Wso2 Oauth after 1.0 Fix from $1,6002023-05-16 MEDIUM 5.4 CVE-2023-33007 Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cross-site scripting (XSS) vuln… Loadcomplete Support after 1.0 Fix from $1,6002023-05-16 HIGH 8.8 CVE-2023-32991 A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows attackers to send an HTTP reque… Saml Single Sign On after 2.0.2 Fix from $1,9502023-05-16 HIGH 8.8 CVE-2023-32992 Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP r… Saml Single Sign On after 2.0.2 Fix from $1,9502023-05-16 HIGH 8.8 CVE-2023-32995 A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers to send an HTTP POST … Saml Single Sign On after 2.0.0 Fix from $1,9502023-05-16 MEDIUM 6.5 CVE-2023-32990 A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect … Azure Vm Agents after 852.v8d35f0960a_43 Fix from $1,6002023-05-16 HIGH 8.8 CVE-2023-32986EPSS 61% Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameter… File Parameters after 285.287.v4b_7b_29d3469d Fix from $1,9502023-05-16 HIGH 8.8 CVE-2023-32987 A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier allows attackers to connect to an attacker-s… Reverse Proxy Auth after 1.7.4 Fix from $1,9502023-05-16 HIGH 8.8 CVE-2023-32989 A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers to connect to an … Azure Vm Agents after 852.v8d35f0960a_43 Fix from $1,9502023-05-16 MEDIUM 5.4 CVE-2023-32984 Jenkins TestNG Results Plugin 730.v4c5283037693 and earlier does not escape several values that are parsed from TestNG report files and displayed on … Testng Results after 730.v4c5283037693 Fix from $1,6002023-05-16 HIGH 8.8 CVE-2023-32981 An arbitrary file write vulnerability in Jenkins Pipeline Utility Steps Plugin 2.15.2 and earlier allows attackers able to provide crafted archives a… Pipeline Utility Steps after 2.15.2 Fix from $1,9502023-05-16 MEDIUM 5.4 CVE-2023-32977 Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-si… Pipeline\ after 1292.v27d8cc3e2602 Fix from $1,6002023-05-16 MEDIUM 5.3 CVE-2023-32983 Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier does not mask extra variables displayed on the configuration form, increasing the potential for… Ansible after 204.v8191fd551eb_f Fix from $1,6002023-05-16 MEDIUM 6.5 CVE-2023-30531 Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing the pot… Consul Kv Builder after 2.0.13 Fix from $1,6002023-04-12 MEDIUM 6.5 CVE-2023-30532 A missing permission check in Jenkins TurboScript Plugin 1.3 and earlier allows attackers with Item/Read permission to trigger builds of jobs corresp… Turboscript after 1.3 Fix from $1,6002023-04-12 MEDIUM 6.5 CVE-2023-30526 A missing permission check in Jenkins Report Portal Plugin 0.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-sp… Report Portal after 0.5 Fix from $1,6002023-04-12 MEDIUM 6.5 CVE-2023-30528 Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for a… Wso2 Oauth after 1.0 Fix from $1,6002023-04-12 HIGH 8.8 CVE-2023-30525 A cross-site request forgery (CSRF) vulnerability in Jenkins Report Portal Plugin 0.5 and earlier allows attackers to connect to an attacker-specifie… Report Portal after 0.5 Fix from $1,9502023-04-12 MEDIUM 5.3 CVE-2023-30521 A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated attackers to trigger builds of … Assembla Merge Request Builder after 1.1.13 Fix from $1,6002023-04-12 MEDIUM 6.5 CVE-2023-30516 Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registr… Image Tag Parameter 2.0+ Fix from $1,6002023-04-12 MEDIUM 5.4 CVE-2023-30520 Jenkins Quay.io trigger Plugin 0.1 and earlier does not limit URL schemes for repository homepage URLs submitted via Quay.io trigger webhooks, result… Quay.io Trigger after 0.1 Fix from $1,6002023-04-12 MEDIUM 5.3 CVE-2023-30517 Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting … Neuvector Vulnerability Scanner after 1.22 Fix from $1,6002023-04-12 MEDIUM 5.3 CVE-2023-30519 A missing permission check in Jenkins Quay.io trigger Plugin 0.1 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding… Quay.io Trigger after 0.1 Fix from $1,6002023-04-12 HIGH 7.5 CVE-2023-30514 Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log whe… Azure Key Vault after 187.va_cd5fecd198a Fix from $1,9502023-04-12