jenkins
1,755 tracked vulnerabilities.
CVE-2019-10375
MEDIUM
Jenkins File System SCM Plugin <2.1 - Info Disclosure
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10374
MEDIUM
Jenkins PegDown Formatter Plugin < 1.3 - Stored Cross-Site Scripting via JavaScript Scheme Links
Aug 07, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10373
MEDIUM
Jenkins Build Pipeline Plugin < 1.5.8 - Stored Cross-Site Scripting via Build Pipeline Description
Aug 07, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10372
MEDIUM
Jenkins Gitlab Authentication Plugin < 1.4 - Open Redirect via GitLabSecurityRealm
Aug 07, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-10371
HIGH
Jenkins Gitlab Auth Plugin <1.4 - Privilege Escalation
Aug 07, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-10370
MEDIUM
Jenkins Mask Passwords Plugin < 2.12.0 - Plaintext Password Exposure in Configuration Form
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10369
MEDIUM
Jenkins JClouds Plugin < 2.14 - Missing Authorization in Test Connection Endpoint
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10368
HIGH
Jenkins JClouds Plugin < 2.14 - Cross-Site Request Forgery via Test Connection Endpoint
Aug 07, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10367
MEDIUM
Jenkins Configuration as Code Plugin < 1.26 - Sensitive Information Exposure in Log Files
Aug 07, 2019
CVSS 5.5
EPSS 0.00
CVE-2019-10366
MEDIUM
Jenkins Skytap Cloud CI Plugin < 2.06 - Insufficiently Protected Credentials in config.xml
Jul 31, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10364
MEDIUM
Jenkins Amazon EC2 Plugin < 1.43 - Private Key Exposure in System Log
Jul 31, 2019
CVSS 5.5
EPSS 0.00
CVE-2019-10363
MEDIUM
Jenkins Configuration as Code Plugin < 1.24 - Cleartext Transmission of Sensitive Information
Jul 31, 2019
CVSS 4.9
EPSS 0.00
CVE-2019-10362
MEDIUM
Jenkins Configuration as Code Plugin <1.24 - Info Disclosure
Jul 31, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10361
MEDIUM
Jenkins Maven Release Plugin < 0.14.0 - Insufficiently Protected Credentials
Jul 31, 2019
CVSS 5.5
EPSS 0.00
CVE-2019-10360
MEDIUM
Jenkins Maven Release Plugin < 0.14.0 - Stored Cross-Site Scripting
Jul 31, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10359
MEDIUM
Jenkins Maven Release Plugin < 0.14.0 - Cross-Site Request Forgery in M2ReleaseAction#doSubmit
Jul 31, 2019
CVSS 6.3
EPSS 0.00
CVE-2019-10358
MEDIUM
Jenkins Maven Integration Plugin < 3.3 - Sensitive Information Exposure in Build Log
Jul 31, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10357
MEDIUM
Jenkins Pipeline < 2.14 - Missing Authorization for SCM Repository Content
Jul 31, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10356
HIGH
Jenkins Script Security Plugin <1.61 - RCE
Jul 31, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10355
HIGH
Jenkins Script Security Plugin <1.61 - RCE
Jul 31, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10345
MEDIUM
Jenkins Configuration as Code Plugin < 1.20 - Insufficiently Protected Credentials
Jul 31, 2019
CVSS 5.5
EPSS 0.00
CVE-2019-10344
MEDIUM
Jenkins Configuration as Code Plugin < 1.24 - Missing Authorization in HTTP Endpoints
Jul 31, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10343
LOW
Jenkins Configuration as Code Plugin < 1.24 - Sensitive Information Exposure in Log Files
Jul 31, 2019
CVSS 3.3
EPSS 0.00
CVE-2019-1010241
MEDIUM
Jenkins Credentials Binding Plugin 1.17 - Info Disclosure
Jul 19, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10354
MEDIUM
Jenkins < 2.176.1 and < 2.185 - Missing Authorization via Stapler Web Framework
Jul 17, 2019
CVSS 4.3
EPSS 0.00
Products
jenkins 259
pipeline\ 37
script_security 33
blue_ocean 11
git 11
email_extension 10
active_directory 9
build_failure_analyzer 9
config_file_provider 9
configuration_as_code 9
ns-nd_integration_performance_publisher 8
credentials_binding 7
github_branch_source 7
html_publisher 7
kubernetes 7
openid_connect_authentication 7
openshift_deployer 7
rundeck 7
subversion 7
amazon_ec2 6
azure_ad 6
azure_vm_agents 6
deployment_dashboard 6
electricflow 6
gerrit_trigger 6
github 6
github_pull_request_builder 6
gitlab 6
google_compute_engine 6
hashicorp_vault 6
Quick Filters