jenkins

1,755 tracked vulnerabilities.

CVE-2020-2179 HIGH
Jenkins Yaml Axis Plugin <= 0.2.0 - Remote Code Execution via Unsafe YAML Deserialization
Apr 16, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-2178 HIGH
Jenkins Parasoft Findings Plugin < 10.4.3 - XML External Entity Injection
Apr 16, 2020
CVSS 7.1
EPSS 0.00
CVE-2020-2177 MEDIUM
Jenkins Copr Plugin < 0.3 - Cleartext Storage of Sensitive Information in Job Config Files
Apr 16, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2176 MEDIUM
Jenkins useMango Runner Plugin < 1.4 - Cross-Site Scripting via useMango Service Values
Apr 07, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2175 MEDIUM
Jenkins FitNesse Plugin < 1.31 - Stored Cross-Site Scripting via Report Content
Apr 07, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2174 MEDIUM
Jenkins AWSEB Deployment Plugin < 0.3.19 - Reflected Cross-Site Scripting via Form Validation Output
Apr 07, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-2173 MEDIUM
Jenkins Gatling Plugin < 1.2.7 - Cross-Site Scripting via Gatling Report Content
Apr 07, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2172 MEDIUM
Jenkins Code Coverage API Plugin < 1.1.4 - XML External Entity Injection
Apr 07, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-2171 HIGH
Jenkins RapidDeploy Plugin < 4.2 - XML External Entity Injection
Mar 25, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-2170 MEDIUM
Jenkins RapidDeploy Plugin < 4.2 - Stored Cross-Site Scripting via Package Name
Mar 25, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2169 MEDIUM
Jenkins Queue Cleanup Plugin < 1.3 - Reflected Cross-Site Scripting via Form Validation Endpoint
Mar 25, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-2168 HIGH
Jenkins Azure Container Service Plugin <= 1.0.1 - Remote Code Execution via YAML Parser
Mar 25, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-2167 HIGH
Jenkins OpenShift Pipeline Plugin <= 1.0.56 - Remote Code Execution via YAML Parser
Mar 25, 2020
CVSS 8.8
EPSS 0.04
CVE-2020-2166 HIGH
Jenkins Pipeline: AWS Steps Plugin < 1.40 - Remote Code Execution via YAML Deserialization
Mar 25, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-2163 MEDIUM
Jenkins < 2.204.5 and < 2.227 - Stored Cross-Site Scripting in List View Column Headers
Mar 25, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2162 MEDIUM
Jenkins < 2.228 - Stored Cross-Site Scripting via Uploaded Build File Parameters
Mar 25, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2161 MEDIUM
Jenkins < 2.204.5 and < 2.227 - Stored Cross-Site Scripting in Node Label Form Validation
Mar 25, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2160 HIGH
Jenkins < 2.204.6 - Cross-Site Request Forgery Protection Bypass via URL Path Representation
Mar 25, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-2159 HIGH
Jenkins CryptoMove Plugin < 0.1.33 - Authenticated OS Command Injection
Mar 09, 2020
CVSS 8.8
EPSS 0.05
CVE-2020-2158 HIGH
Jenkins Literate Plugin < 1.0 - Remote Code Execution via YAML Deserialization
Mar 09, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-2157 MEDIUM
Jenkins Skytap Cloud CI Plugin <= 2.07 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2156 MEDIUM
Jenkins DeployHub Plugin <= 8.0.14 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2155 MEDIUM
Jenkins OpenShift Deployer Plugin <= 1.2.0 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-2154 MEDIUM
Jenkins Zephyr for JIRA Test Management Plugin < 1.5 - Cleartext Storage of Sensitive Information
Mar 09, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-2153 MEDIUM
Jenkins Backlog Plugin < 2.4 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 4.3
EPSS 0.00