org.jenkins-ci.plugins

1,024 tracked vulnerabilities.

CVE-2020-2175 MEDIUM
Jenkins FitNesse Plugin < 1.31 - Stored Cross-Site Scripting via Report Content
Apr 07, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2173 MEDIUM
Jenkins Gatling Plugin < 1.2.7 - Cross-Site Scripting via Gatling Report Content
Apr 07, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2171 HIGH
Jenkins RapidDeploy Plugin < 4.2 - XML External Entity Injection
Mar 25, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-2170 MEDIUM
Jenkins RapidDeploy Plugin < 4.2 - Stored Cross-Site Scripting via Package Name
Mar 25, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2169 MEDIUM
Jenkins Queue Cleanup Plugin < 1.3 - Reflected Cross-Site Scripting via Form Validation Endpoint
Mar 25, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-2168 HIGH
Jenkins Azure Container Service Plugin <= 1.0.1 - Remote Code Execution via YAML Parser
Mar 25, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-2165 HIGH
Jenkins Artifactory Plugin <= 3.6.0 - Plaintext Password Exposure in Global Configuration
Mar 25, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-2164 MEDIUM
Jenkins Artifactory Plugin <= 3.5.0 - Unprotected Credential Storage
Mar 25, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-2158 HIGH
Jenkins Literate Plugin < 1.0 - Remote Code Execution via YAML Deserialization
Mar 09, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-2157 MEDIUM
Jenkins Skytap Cloud CI Plugin <= 2.07 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2155 MEDIUM
Jenkins OpenShift Deployer Plugin <= 1.2.0 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-2154 MEDIUM
Jenkins Zephyr for JIRA Test Management Plugin < 1.5 - Cleartext Storage of Sensitive Information
Mar 09, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-2153 MEDIUM
Jenkins Backlog Plugin < 2.4 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2151 MEDIUM
Jenkins Quality Gates Plugin < 2.5 - Cleartext Transmission of Sensitive Information in Global Configuration Form
Mar 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-2150 MEDIUM
Jenkins Sonar Quality Gates Plugin < 1.3.1 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-2149 MEDIUM
Jenkins Repository Connector Plugin < 1.2.6 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-2145 MEDIUM
Jenkins Zephyr Enterprise Test Management Plugin < 1.9.1 - Insufficiently Protected Credentials
Mar 09, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-2144 HIGH
Jenkins Rundeck Plugin < 3.6.6 - XML External Entity Injection
Mar 09, 2020
CVSS 7.1
EPSS 0.00
CVE-2020-2143 MEDIUM
Jenkins Logstash Plugin < 2.3.1 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-2142 MEDIUM
Jenkins P4 Plugin < 1.10.10 - Unauthenticated Build Trigger via Missing Permission Check
Mar 09, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2141 MEDIUM
Jenkins P4 Plugin < 1.10.10 - Cross-Site Request Forgery
Mar 09, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2140 MEDIUM NUCLEI
Jenkins Audit Trail Plugin < 3.2 - Reflected Cross-Site Scripting via URL Patterns Field
Mar 09, 2020
CVSS 6.1
EPSS 0.45
CVE-2020-2139 MEDIUM
Jenkins Cobertura < 1.16 - Arbitrary File Write via Coverage Report File
Mar 09, 2020
CVSS 6.5
EPSS 0.05
CVE-2020-2138 HIGH
Jenkins Cobertura Plugin < 1.15 - XML External Entity Injection
Mar 09, 2020
CVSS 7.1
EPSS 0.00
CVE-2020-2137 MEDIUM
Jenkins Timestamper Plugin <= 1.11.1 - Stored Cross-Site Scripting
Mar 09, 2020
CVSS 4.8
EPSS 0.00