jenkins

1,755 tracked vulnerabilities.

CVE-2020-2127 MEDIUM
Jenkins BMC Release Package and Deployment Plugin < 1.1 - Unencrypted Credential Storage
Feb 12, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2126 MEDIUM
Jenkins DigitalOcean Plugin <= 1.1 - Insufficiently Protected Credentials
Feb 12, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2125 MEDIUM
Jenkins Debian Package Builder Plugin < 1.6.11 - Insufficiently Protected Credentials
Feb 12, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2124 MEDIUM
Jenkins Dynamic Extended Choice Parameter Plugin < 1.0.1 - Insufficiently Protected Credentials
Feb 12, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2123 HIGH
Jenkins RadarGun Plugin < 1.7 - Remote Code Execution via YAML Deserialization
Feb 12, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-2122 MEDIUM
Jenkins Brakeman Plugin < 0.12 - Stored Cross-Site Scripting via Unescaped JSON Values
Feb 12, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2121 HIGH
Jenkins Google Kubernetes Engine Plugin < 0.8.0 - Remote Code Execution via YAML Parser
Feb 12, 2020
CVSS 8.8
EPSS 0.02
CVE-2020-2120 HIGH
Jenkins FitNesse Plugin < 1.30 - XML External Entity Injection
Feb 12, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-2119 MEDIUM
Jenkins Azure AD Plugin <= 1.1.2 - Insufficiently Protected Credentials
Feb 12, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-2118 MEDIUM
Jenkins Pipeline GitHub Notify Step Plugin < 1.0.4 - Credential ID Enumeration via Form-Related Methods
Feb 12, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2117 MEDIUM
Jenkins Pipeline GitHub Notify Step Plugin < 1.0.4 - Missing Permission Check
Feb 12, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2116 HIGH
Jenkins Pipeline GitHub Notify Step < 1.0.4 - Cross-Site Request Forgery
Feb 12, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-2115 HIGH
Jenkins NUnit < 0.25 - XML External Entity Injection
Feb 12, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-2114 HIGH
Jenkins S3 Publisher Plugin <= 0.11.4 - Plaintext Credential Exposure in Global Configuration
Feb 12, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-2113 MEDIUM
Jenkins Git Parameter Plugin < 0.9.11 - Stored Cross-Site Scripting via Default Value
Feb 12, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2112 MEDIUM
Jenkins Git Parameter Plugin <= 0.9.11 - Stored Cross-Site Scripting in Parameter Name
Feb 12, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2111 MEDIUM
Jenkins Subversion Plugin < 2.13.0 - Stored Cross-Site Scripting in Project Repository Base URL Field
Feb 12, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2110 HIGH
Jenkins Script Security Plugin < 1.69 - Sandbox Bypass via AST Transforming Annotations
Feb 12, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-2109 HIGH
Jenkins Pipeline < 2.78 - Sandbox Protection Bypass via Default Parameter Expressions
Feb 12, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-2108 HIGH
Jenkins WebSphere Deployer Plugin < 1.6.1 - XML External Entity Injection via Job Configuration
Jan 29, 2020
CVSS 7.6
EPSS 0.00
CVE-2020-2107 MEDIUM
Jenkins Fortify Plugin < 19.1.29 - Insufficiently Protected Credentials in Job config.xml
Jan 29, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2106 MEDIUM
Jenkins Code Coverage API Plugin < 1.1.2 - Stored Cross-Site Scripting in Coverage Report Filename
Jan 29, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2105 MEDIUM
Jenkins < 2.204.1 and < 2.218 - Clickjacking via REST API Endpoints
Jan 29, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2104 MEDIUM
Jenkins < 2.204.1 and < 2.218 - Incorrect Authorization for JVM Memory Usage Chart
Jan 29, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2103 MEDIUM NUCLEI
Jenkins < 2.204.1, 2.205-2.218 - Exposure of Sensitive Information via whoAmI Diagnostic Page
Jan 29, 2020
CVSS 5.4
EPSS 0.45