jenkins

1,755 tracked vulnerabilities.

CVE-2019-10319 MEDIUM
Jenkins PAM Authentication Plugin 1.5 and earlier - Missing Authorization in PamSecurityRealm.DescriptorImpl#doTest
May 21, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10318 HIGH
Jenkins Azure AD Plugin <= 0.3.3 - Insufficiently Protected Credentials in Global Configuration
Apr 30, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10317 MEDIUM
Jenkins SiteMonitor Plugin < 0.5 - SSL/TLS and Hostname Verification Disabled
Apr 30, 2019
CVSS 5.9
EPSS 0.00
CVE-2019-10316 HIGH
Jenkins Aqua MicroScanner Plugin <= 1.0.5 - Insufficiently Protected Credentials
Apr 30, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10315 HIGH
Jenkins GitHub Authentication Plugin < 0.31 - Cross-Site Request Forgery via OAuth State Parameter
Apr 30, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10314 MEDIUM
Jenkins Koji Plugin < 0.3 - Improper Certificate Validation
Apr 30, 2019
CVSS 5.9
EPSS 0.00
CVE-2019-10313 HIGH
Jenkins Twitter Plugin < 0.7 - Insufficiently Protected Credentials
Apr 30, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10312 MEDIUM
Jenkins Ansible Tower Plugin <= 0.9.1 - Missing Authorization in TowerInstallation Descriptor
Apr 30, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10311 HIGH
Jenkins Ansible Tower Plugin < 0.9.1 - Missing Authorization in TowerInstallation Connection Test
Apr 30, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10310 HIGH
Jenkins Ansible Tower Plugin < 0.9.1 - Cross-Site Request Forgery via TowerInstallation Connection Test
Apr 30, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10309 CRITICAL
Jenkins Self-Organizing Swarm Modules Plugin - XML External Entity Injection via UDP Broadcast Response
Apr 30, 2019
CVSS 9.3
EPSS 0.00
CVE-2019-10308 MEDIUM
Jenkins Static Analysis Utilities < 1.95 - Missing Authorization in DefaultGraphConfigurationView#doSave
Apr 30, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10307 MEDIUM
Jenkins Static Analysis Utilities Plugin < 1.95 - Cross-Site Request Forgery via DefaultGraphConfigurationView#doSave
Apr 30, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10306 CRITICAL
Jenkins ontrack < 3.4 - Sandbox Bypass via DSL Definition
Apr 18, 2019
CVSS 9.9
EPSS 0.00
CVE-2019-10305 MEDIUM
Jenkins XebiaLabs XL Deploy Plugin < 7.5.3 - Missing Authorization in Credential Validation
Apr 18, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10304 MEDIUM
Jenkins XebiaLabs XL Deploy Plugin < 7.5.3 - Cross-Site Request Forgery via Credential Form Validation
Apr 18, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10303 HIGH
Jenkins Azure PublisherSettings Credentials Plugin < 1.2 - Insufficiently Protected Credentials
Apr 18, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10302 HIGH
Jenkins jira-ext < 0.8 - Insufficiently Protected Credentials
Apr 18, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10301 HIGH
Jenkins GitLab Plugin < 1.5.11 - Missing Authorization in Connection Test
Apr 18, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10300 HIGH
Jenkins GitLab Plugin < 1.5.11 - Cross-Site Request Forgery via Test Connection Form
Apr 18, 2019
CVSS 8.0
EPSS 0.00
CVE-2019-1003050 MEDIUM
Jenkins < 2.164.2 - Stored Cross-Site Scripting via Job URL in f:validateButton
Apr 10, 2019
CVSS 5.4
EPSS 0.01
CVE-2019-1003049 HIGH
Jenkins < 2.164.1 and < 2.171 - Insufficient Session Expiration
Apr 10, 2019
CVSS 8.1
EPSS 0.00
CVE-2019-10299 HIGH
Jenkins CloudCoreo DeployTime Plugin - Insufficiently Protected Credentials
Apr 04, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10298 HIGH
Jenkins Koji Plugin - Insufficiently Protected Credentials
Apr 04, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10297 HIGH
Jenkins Sametime Plugin - Insufficiently Protected Credentials
Apr 04, 2019
CVSS 8.8
EPSS 0.00