jenkins

1,755 tracked vulnerabilities.

CVE-2017-1000107 HIGH
Script Security Plugin - Code Injection
Oct 05, 2017
CVSS 8.8
EPSS 0.00
CVE-2017-1000106 HIGH
Blue Ocean < 1.1.5 - Unauthenticated Arbitrary Commit and File Read via SCM Content REST API
Oct 05, 2017
CVSS 8.5
EPSS 0.00
CVE-2017-1000105 MEDIUM
Blue Ocean - Missing Authorization for Archived Artifacts
Oct 05, 2017
CVSS 5.3
EPSS 0.00
CVE-2017-1000104 MEDIUM
Config File Provider Plugin < 2.16.1 - Unauthenticated Sensitive File Access
Oct 05, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-1000103 MEDIUM
Static Analysis Utilities - DRY Plugin - XSS
Oct 05, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-1000102 MEDIUM
Static Analysis Utilities < 1.91 - Stored Cross-Site Scripting in Details View
Oct 05, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-1000096 HIGH
Jenkins Pipeline < 2.36 - Arbitrary Code Execution via Incomplete Sandbox Protection
Oct 05, 2017
CVSS 8.8
EPSS 0.00
CVE-2017-1000095 MEDIUM
Jenkins Script Security < 1.29.1 - Sandbox Bypass via DefaultGroovyMethods Whitelist
Oct 05, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-1000094 MEDIUM
Docker Commons Plugin - Info Disclosure
Oct 05, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-1000093 HIGH
Poll SCM Plugin < 1.3.1 - Cross-Site Request Forgery via API
Oct 05, 2017
CVSS 8.8
EPSS 0.00
CVE-2017-1000092 HIGH
Jenkins Git Plugin - Cross-Site Request Forgery via Form Validation
Oct 05, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-1000091 MEDIUM
GitHub Branch Source Plugin - Cross-Site Request Forgery via Form Validation
Oct 05, 2017
CVSS 6.3
EPSS 0.00
CVE-2017-1000090 HIGH
Role-based Authorization Strategy Plugin - CSRF
Oct 05, 2017
CVSS 8.8
EPSS 0.00
CVE-2017-1000089 MEDIUM
Jenkins Pipeline < 2.5 and pipeline-build-step < 2.5.1 - Unauthenticated Arbitrary Project Triggering
Oct 05, 2017
CVSS 5.3
EPSS 0.00
CVE-2017-1000088 MEDIUM
Sidebar Link Plugin < 1.8 - Stored Cross-Site Scripting via Sidebar Link Configuration
Oct 05, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-1000087 MEDIUM
GitHub Branch Source - Info Disclosure
Oct 05, 2017
CVSS 4.3
EPSS 0.00
CVE-2017-1000086 HIGH
Periodic Backup Plugin - Privilege Escalation & CSRF
Oct 05, 2017
CVSS 8.0
EPSS 0.00
CVE-2017-1000085 MEDIUM
Subversion Plugin - Info Disclosure
Oct 05, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-1000084 MEDIUM
Jenkins Parameterized Trigger Plugin - Unauthenticated Arbitrary Project Triggering
Oct 05, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-1000362 CRITICAL
Jenkins 1.498-2.32.1 - Unprotected Sensitive Data Exposure via Re-key Admin Monitor Backups
Jul 17, 2017
CVSS 9.8
EPSS 0.01
CVE-2016-4988 MEDIUM
Jenkins Build Failure Analyzer < 1.16.0 - Cross-Site Scripting
Feb 09, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-4987 MEDIUM
Jenkins Image Gallery < 1.4 - Path Traversal
Feb 09, 2017
CVSS 6.5
EPSS 0.00
CVE-2016-4986 HIGH
Jenkins Tap < 1.25 - Path Traversal
Feb 09, 2017
CVSS 7.5
EPSS 0.00
CVE-2016-3102 HIGH
Jenkins Script Security Plugin < 1.18.1 - Sandbox Bypass via Direct Field Access or Array Operations
Feb 09, 2017
CVSS 7.3
EPSS 0.00
CVE-2016-3101 MEDIUM
Jenkins Extra Columns < 1.17 - Cross-Site Scripting via Unfiltered Tooltip Markup
Feb 09, 2017
CVSS 5.4
EPSS 0.00