jenkins

1,755 tracked vulnerabilities.

CVE-2019-10401 MEDIUM
Jenkins < 2.176.3, < 2.196 - Stored Cross-Site Scripting via f:expandableTextBox Form Control
Sep 25, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10400 MEDIUM
Jenkins Script Security Plugin <1.62 - RCE
Sep 12, 2019
CVSS 4.2
EPSS 0.00
CVE-2019-10399 MEDIUM
Jenkins Script Security Plugin <1.62 - RCE
Sep 12, 2019
CVSS 4.2
EPSS 0.00
CVE-2019-10398 MEDIUM
Jenkins Beaker Builder Plugin < 1.9 - Insufficiently Protected Credentials
Sep 12, 2019
CVSS 5.5
EPSS 0.00
CVE-2019-10397 LOW
Jenkins Aqua Security Serverless Scanner < 1.0.4 - Cleartext Transmission of Sensitive Information
Sep 12, 2019
CVSS 3.1
EPSS 0.00
CVE-2019-10396 MEDIUM
Jenkins Dashboard View Plugin < 2.11 - Stored Cross-Site Scripting via Build Descriptions
Sep 12, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10395 MEDIUM
Jenkins Build Environment Plugin < 1.6 - Cross-Site Scripting via Unescaped Variables
Sep 12, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10394 MEDIUM
Jenkins Script Security Plugin <1.62 - RCE
Sep 12, 2019
CVSS 4.2
EPSS 0.00
CVE-2019-10393 MEDIUM
Jenkins Script Security Plugin <1.62 - RCE
Sep 12, 2019
CVSS 4.2
EPSS 0.00
CVE-2019-10392 HIGH
Jenkins Git Client Plugin < 2.8.4 - OS Command Injection via Git ls-remote URL Argument
Sep 12, 2019
CVSS 8.8
EPSS 0.74
CVE-2019-10391 MEDIUM
Jenkins IBM Application Security on Cloud Plugin < 1.2.4 - Cleartext Transmission of Sensitive Information
Aug 28, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10390 HIGH
Jenkins Splunk Plugin < 1.7.4 - Authenticated Remote Code Execution via Groovy Script Endpoint
Aug 28, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10384 HIGH
Jenkins < 2.176.3 - Cross-Site Request Forgery via Non-Expiring CSRF Tokens
Aug 28, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10383 MEDIUM
Jenkins < 2.176.3 - Authenticated Stored Cross-Site Scripting via Update Site URL Configuration
Aug 28, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-10389 MEDIUM
Jenkins Relution Enterprise Appstore Publisher < 1.24 - Server-Side Request Forgery
Aug 07, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10388 MEDIUM
Jenkins Relution Enterprise Appstore Publisher < 1.24 - Cross-Site Request Forgery
Aug 07, 2019
CVSS 4.3
EPSS 0.01
CVE-2019-10387 MEDIUM
Jenkins XL TestView Plugin < 1.2.0 - Missing Authorization in XLTestView.XLTestDescriptor#doTestConnection
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10386 HIGH
Jenkins XL TestView Plugin < 1.2.0 - Cross-Site Request Forgery via Test Connection Endpoint
Aug 07, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10385 MEDIUM
Jenkins eggPlant Plugin < 2.2 - Insufficiently Protected Credentials in Job Config Files
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10382 MEDIUM
Jenkins VMware Lab Manager Slaves Plugin <= 0.2.8 - Improper Certificate Validation
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10381 HIGH
Jenkins Codefresh Integration Plugin < 1.8 - SSL/TLS and Hostname Verification Disabled
Aug 07, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-10380 HIGH
Jenkins Simple Travis Pipeline Runner Plugin <1.0 - RCE
Aug 07, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10378 MEDIUM
Jenkins TestLink Plugin <= 3.16 - Insufficiently Protected Credentials
Aug 07, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-10377 MEDIUM
Jenkins Avatar Plugin < 1.2 - Missing Authorization for User Avatar Changes
Aug 07, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10376 MEDIUM
Jenkins Wall Display Plugin < 0.6.34 - Reflected Cross-Site Scripting
Aug 07, 2019
CVSS 6.1
EPSS 0.00