jenkins

1,755 tracked vulnerabilities.

CVE-2023-30527 MEDIUM
Jenkins WSO2 Oauth Plugin < 1.0 - Cleartext Storage of Sensitive Information in Global Config
Apr 12, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-30526 MEDIUM
Jenkins Report Portal Plugin < 0.5 - Missing Authorization for URL Connection with Bearer Token
Apr 12, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-30525 HIGH
Jenkins Report Portal Plugin < 0.5 - Cross-Site Request Forgery
Apr 12, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-30524 MEDIUM
Jenkins Report Portal Plugin <0.5 - Info Disclosure
Apr 12, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-30523 MEDIUM
Jenkins Report Portal Plugin <= 0.5 - Cleartext Storage of Sensitive Information in Job Configuration
Apr 12, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-30522 MEDIUM
Jenkins Fogbugz Plugin < 2.2.17 - Missing Authorization via Jobname Parameter
Apr 12, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-30521 MEDIUM
Jenkins Assembla Merge Request Builder < 1.1.13 - Unauthenticated Build Triggering
Apr 12, 2023
CVSS 5.3
EPSS 0.01
CVE-2023-30520 MEDIUM
Jenkins Quay.io trigger Plugin <= 0.1 - Stored Cross-Site Scripting via Repository Homepage URL
Apr 12, 2023
CVSS 5.4
EPSS 0.09
CVE-2023-30519 MEDIUM
Jenkins Quay.io trigger Plugin 0.1 - Unauthenticated Missing Authorization
Apr 12, 2023
CVSS 5.3
EPSS 0.01
CVE-2023-30518 MEDIUM
Jenkins Thycotic Secret Server Plugin < 1.0.2 - Missing Authorization for Credential ID Enumeration
Apr 12, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-30517 MEDIUM
Jenkins NeuVector Vulnerability Scanner < 1.22 - Improper Certificate Validation
Apr 12, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-30516 MEDIUM
Jenkins Image Tag Parameter Plugin < 2.0 - Improper Certificate Validation
Apr 12, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-30515 HIGH
Jenkins Thycotic DevOps Secrets Vault Plugin < 1.0.0 - Cleartext Transmission of Sensitive Information in Build Log
Apr 12, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-30514 HIGH
Jenkins Azure Key Vault Plugin < 187.va_cd5fecd198a - Credential Exposure in Build Log
Apr 12, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-30513 HIGH
Jenkins Kubernetes Plugin < 3909.v1f2c633e8590 - Cleartext Transmission of Sensitive Information in Build Log
Apr 12, 2023
CVSS 7.5
EPSS 0.01
CVE-2023-28684 MEDIUM
Jenkins remote-jobs-view-plugin <0.0.3 - XXE
Apr 02, 2023
CVSS 6.5
EPSS 0.02
CVE-2023-28683 HIGH
Jenkins Phabricator Differential Plugin <2.1.5 - XXE
Apr 02, 2023
CVSS 8.2
EPSS 0.01
CVE-2023-28682 HIGH
Jenkins Performance Publisher Plugin <8.09 - XXE
Apr 02, 2023
CVSS 8.2
EPSS 0.01
CVE-2023-28681 HIGH
Jenkins Visual Studio Code Metrics Plugin <1.7 - XXE
Apr 02, 2023
CVSS 8.2
EPSS 0.00
CVE-2023-28680 HIGH
Jenkins Crap4J Plugin < 0.9 - XML External Entity Injection
Apr 02, 2023
CVSS 7.5
EPSS 0.02
CVE-2023-28679 MEDIUM
Jenkins Mashup Portlets Plugin <1.1.2 - XSS
Apr 02, 2023
CVSS 5.4
EPSS 0.13
CVE-2023-28678 MEDIUM
Jenkins Cppcheck Plugin <1.26 - XSS
Apr 02, 2023
CVSS 5.4
EPSS 0.09
CVE-2023-28677 CRITICAL
Jenkins Convert To Pipeline Plugin <1.0 - RCE
Apr 02, 2023
CVSS 9.8
EPSS 0.02
CVE-2023-28676 HIGH
Jenkins Convert To Pipeline Plugin <1.0 - CSRF
Apr 02, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-28675 MEDIUM
Jenkins OctoPerf Load Testing Plugin <4.5.2 - Privilege Escalation
Apr 02, 2023
CVSS 4.3
EPSS 0.01