jenkins
1,755 tracked vulnerabilities.
CVE-2019-10401
MEDIUM
Jenkins < 2.176.3, < 2.196 - Stored Cross-Site Scripting via f:expandableTextBox Form Control
Sep 25, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10400
MEDIUM
Jenkins Script Security Plugin <1.62 - RCE
Sep 12, 2019
CVSS 4.2
EPSS 0.00
CVE-2019-10399
MEDIUM
Jenkins Script Security Plugin <1.62 - RCE
Sep 12, 2019
CVSS 4.2
EPSS 0.00
CVE-2019-10398
MEDIUM
Jenkins Beaker Builder Plugin < 1.9 - Insufficiently Protected Credentials
Sep 12, 2019
CVSS 5.5
EPSS 0.00
CVE-2019-10397
LOW
Jenkins Aqua Security Serverless Scanner < 1.0.4 - Cleartext Transmission of Sensitive Information
Sep 12, 2019
CVSS 3.1
EPSS 0.00
CVE-2019-10396
MEDIUM
Jenkins Dashboard View Plugin < 2.11 - Stored Cross-Site Scripting via Build Descriptions
Sep 12, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10395
MEDIUM
Jenkins Build Environment Plugin < 1.6 - Cross-Site Scripting via Unescaped Variables
Sep 12, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10394
MEDIUM
Jenkins Script Security Plugin <1.62 - RCE
Sep 12, 2019
CVSS 4.2
EPSS 0.00
CVE-2019-10393
MEDIUM
Jenkins Script Security Plugin <1.62 - RCE
Sep 12, 2019
CVSS 4.2
EPSS 0.00
CVE-2019-10392
HIGH
Jenkins Git Client Plugin < 2.8.4 - OS Command Injection via Git ls-remote URL Argument
Sep 12, 2019
CVSS 8.8
EPSS 0.74
CVE-2019-10391
MEDIUM
Jenkins IBM Application Security on Cloud Plugin < 1.2.4 - Cleartext Transmission of Sensitive Information
Aug 28, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10390
HIGH
Jenkins Splunk Plugin < 1.7.4 - Authenticated Remote Code Execution via Groovy Script Endpoint
Aug 28, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10384
HIGH
Jenkins < 2.176.3 - Cross-Site Request Forgery via Non-Expiring CSRF Tokens
Aug 28, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10383
MEDIUM
Jenkins < 2.176.3 - Authenticated Stored Cross-Site Scripting via Update Site URL Configuration
Aug 28, 2019
CVSS 4.8
EPSS 0.00
CVE-2019-10389
MEDIUM
Jenkins Relution Enterprise Appstore Publisher < 1.24 - Server-Side Request Forgery
Aug 07, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10388
MEDIUM
Jenkins Relution Enterprise Appstore Publisher < 1.24 - Cross-Site Request Forgery
Aug 07, 2019
CVSS 4.3
EPSS 0.01
CVE-2019-10387
MEDIUM
Jenkins XL TestView Plugin < 1.2.0 - Missing Authorization in XLTestView.XLTestDescriptor#doTestConnection
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10386
HIGH
Jenkins XL TestView Plugin < 1.2.0 - Cross-Site Request Forgery via Test Connection Endpoint
Aug 07, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10385
MEDIUM
Jenkins eggPlant Plugin < 2.2 - Insufficiently Protected Credentials in Job Config Files
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10382
MEDIUM
Jenkins VMware Lab Manager Slaves Plugin <= 0.2.8 - Improper Certificate Validation
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10381
HIGH
Jenkins Codefresh Integration Plugin < 1.8 - SSL/TLS and Hostname Verification Disabled
Aug 07, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-10380
HIGH
Jenkins Simple Travis Pipeline Runner Plugin <1.0 - RCE
Aug 07, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10378
MEDIUM
Jenkins TestLink Plugin <= 3.16 - Insufficiently Protected Credentials
Aug 07, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-10377
MEDIUM
Jenkins Avatar Plugin < 1.2 - Missing Authorization for User Avatar Changes
Aug 07, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10376
MEDIUM
Jenkins Wall Display Plugin < 0.6.34 - Reflected Cross-Site Scripting
Aug 07, 2019
CVSS 6.1
EPSS 0.00
Products
jenkins 259
pipeline\ 37
script_security 33
blue_ocean 11
git 11
email_extension 10
active_directory 9
build_failure_analyzer 9
config_file_provider 9
configuration_as_code 9
ns-nd_integration_performance_publisher 8
credentials_binding 7
github_branch_source 7
html_publisher 7
kubernetes 7
openid_connect_authentication 7
openshift_deployer 7
rundeck 7
subversion 7
amazon_ec2 6
azure_ad 6
azure_vm_agents 6
deployment_dashboard 6
electricflow 6
gerrit_trigger 6
github 6
github_pull_request_builder 6
gitlab 6
google_compute_engine 6
hashicorp_vault 6
Quick Filters