org.jenkins-ci.plugins
1,024 tracked vulnerabilities.
CVE-2020-2175
MEDIUM
Jenkins FitNesse Plugin < 1.31 - Stored Cross-Site Scripting via Report Content
Apr 07, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2173
MEDIUM
Jenkins Gatling Plugin < 1.2.7 - Cross-Site Scripting via Gatling Report Content
Apr 07, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2171
HIGH
Jenkins RapidDeploy Plugin < 4.2 - XML External Entity Injection
Mar 25, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-2170
MEDIUM
Jenkins RapidDeploy Plugin < 4.2 - Stored Cross-Site Scripting via Package Name
Mar 25, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-2169
MEDIUM
Jenkins Queue Cleanup Plugin < 1.3 - Reflected Cross-Site Scripting via Form Validation Endpoint
Mar 25, 2020
CVSS 6.1
EPSS 0.00
CVE-2020-2168
HIGH
Jenkins Azure Container Service Plugin <= 1.0.1 - Remote Code Execution via YAML Parser
Mar 25, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-2165
HIGH
Jenkins Artifactory Plugin <= 3.6.0 - Plaintext Password Exposure in Global Configuration
Mar 25, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-2164
MEDIUM
Jenkins Artifactory Plugin <= 3.5.0 - Unprotected Credential Storage
Mar 25, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-2158
HIGH
Jenkins Literate Plugin < 1.0 - Remote Code Execution via YAML Deserialization
Mar 09, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-2157
MEDIUM
Jenkins Skytap Cloud CI Plugin <= 2.07 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2155
MEDIUM
Jenkins OpenShift Deployer Plugin <= 1.2.0 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-2154
MEDIUM
Jenkins Zephyr for JIRA Test Management Plugin < 1.5 - Cleartext Storage of Sensitive Information
Mar 09, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-2153
MEDIUM
Jenkins Backlog Plugin < 2.4 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2151
MEDIUM
Jenkins Quality Gates Plugin < 2.5 - Cleartext Transmission of Sensitive Information in Global Configuration Form
Mar 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-2150
MEDIUM
Jenkins Sonar Quality Gates Plugin < 1.3.1 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-2149
MEDIUM
Jenkins Repository Connector Plugin < 1.2.6 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-2145
MEDIUM
Jenkins Zephyr Enterprise Test Management Plugin < 1.9.1 - Insufficiently Protected Credentials
Mar 09, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-2144
HIGH
Jenkins Rundeck Plugin < 3.6.6 - XML External Entity Injection
Mar 09, 2020
CVSS 7.1
EPSS 0.00
CVE-2020-2143
MEDIUM
Jenkins Logstash Plugin < 2.3.1 - Cleartext Transmission of Sensitive Credentials
Mar 09, 2020
CVSS 5.3
EPSS 0.00
CVE-2020-2142
MEDIUM
Jenkins P4 Plugin < 1.10.10 - Unauthenticated Build Trigger via Missing Permission Check
Mar 09, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2141
MEDIUM
Jenkins P4 Plugin < 1.10.10 - Cross-Site Request Forgery
Mar 09, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-2140
MEDIUM
NUCLEI
Jenkins Audit Trail Plugin < 3.2 - Reflected Cross-Site Scripting via URL Patterns Field
Mar 09, 2020
CVSS 6.1
EPSS 0.45
CVE-2020-2139
MEDIUM
Jenkins Cobertura < 1.16 - Arbitrary File Write via Coverage Report File
Mar 09, 2020
CVSS 6.5
EPSS 0.05
CVE-2020-2138
HIGH
Jenkins Cobertura Plugin < 1.15 - XML External Entity Injection
Mar 09, 2020
CVSS 7.1
EPSS 0.00
CVE-2020-2137
MEDIUM
Jenkins Timestamper Plugin <= 1.11.1 - Stored Cross-Site Scripting
Mar 09, 2020
CVSS 4.8
EPSS 0.00
Products
script-security 35
git 13
email-ext 11
active-directory 9
config-file-provider 9
electricflow 9
ec2 8
oic-auth 8
subversion 8
artifactory 7
credentials-binding 7
htmlpublisher 7
jobConfigHistory 7
mercurial 7
openshift-deployer 7
rundeck 7
azure-ad 6
azure-vm-agents 6
ec2-deployment-dashboard 6
fortify-on-demand-uploader 6
ghprb 6
gitlab-oauth 6
gitlab-plugin 6
pipeline-maven 6
repository-connector 6
aws-codecommit-trigger 5
codedx 5
credentials 5
delphix 5
extended-choice-parameter 5
Quick Filters