org.jenkins-ci.plugins
1,024 tracked vulnerabilities.
CVE-2019-10393
MEDIUM
Jenkins Script Security Plugin <1.62 - RCE
Sep 12, 2019
CVSS 4.2
EPSS 0.00
CVE-2019-10392
HIGH
Jenkins Git Client Plugin < 2.8.4 - OS Command Injection via Git ls-remote URL Argument
Sep 12, 2019
CVSS 8.8
EPSS 0.74
CVE-2019-10389
MEDIUM
Jenkins Relution Enterprise Appstore Publisher < 1.24 - Server-Side Request Forgery
Aug 07, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10388
MEDIUM
Jenkins Relution Enterprise Appstore Publisher < 1.24 - Cross-Site Request Forgery
Aug 07, 2019
CVSS 4.3
EPSS 0.01
CVE-2019-10385
MEDIUM
Jenkins eggPlant Plugin < 2.2 - Insufficiently Protected Credentials in Job Config Files
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10382
MEDIUM
Jenkins VMware Lab Manager Slaves Plugin <= 0.2.8 - Improper Certificate Validation
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10381
HIGH
Jenkins Codefresh Integration Plugin < 1.8 - SSL/TLS and Hostname Verification Disabled
Aug 07, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-10380
HIGH
Jenkins Simple Travis Pipeline Runner Plugin <1.0 - RCE
Aug 07, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10379
MEDIUM
Google Cloud Messaging Notification < 1.0 - Insufficiently Protected Credentials
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10378
MEDIUM
Jenkins TestLink Plugin <= 3.16 - Insufficiently Protected Credentials
Aug 07, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-10376
MEDIUM
Jenkins Wall Display Plugin < 0.6.34 - Reflected Cross-Site Scripting
Aug 07, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-10374
MEDIUM
Jenkins PegDown Formatter Plugin < 1.3 - Stored Cross-Site Scripting via JavaScript Scheme Links
Aug 07, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10373
MEDIUM
Jenkins Build Pipeline Plugin < 1.5.8 - Stored Cross-Site Scripting via Build Pipeline Description
Aug 07, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10372
MEDIUM
Jenkins Gitlab Authentication Plugin < 1.4 - Open Redirect via GitLabSecurityRealm
Aug 07, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-10371
HIGH
Jenkins Gitlab Auth Plugin <1.4 - Privilege Escalation
Aug 07, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-10370
MEDIUM
Jenkins Mask Passwords Plugin < 2.12.0 - Plaintext Password Exposure in Configuration Form
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10369
MEDIUM
Jenkins JClouds Plugin < 2.14 - Missing Authorization in Test Connection Endpoint
Aug 07, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10368
HIGH
Jenkins JClouds Plugin < 2.14 - Cross-Site Request Forgery via Test Connection Endpoint
Aug 07, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10366
MEDIUM
Jenkins Skytap Cloud CI Plugin < 2.06 - Insufficiently Protected Credentials in config.xml
Jul 31, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10365
MEDIUM
Jenkins Google Kubernetes Engine Plugin <= 0.6.2 - Unauthorized Access Token Exposure via Temporary File
Jul 31, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10364
MEDIUM
Jenkins Amazon EC2 Plugin < 1.43 - Private Key Exposure in System Log
Jul 31, 2019
CVSS 5.5
EPSS 0.00
CVE-2019-10356
HIGH
Jenkins Script Security Plugin <1.61 - RCE
Jul 31, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10355
HIGH
Jenkins Script Security Plugin <1.61 - RCE
Jul 31, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-1010241
MEDIUM
Jenkins Credentials Binding Plugin 1.17 - Info Disclosure
Jul 19, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10350
HIGH
Jenkins Port Allocator Plugin < 1.8 - Cleartext Storage of Sensitive Information in Job Config Files
Jul 11, 2019
CVSS 8.8
EPSS 0.00
Products
script-security 35
git 13
email-ext 11
active-directory 9
config-file-provider 9
electricflow 9
ec2 8
oic-auth 8
subversion 8
artifactory 7
credentials-binding 7
htmlpublisher 7
jobConfigHistory 7
mercurial 7
openshift-deployer 7
rundeck 7
azure-ad 6
azure-vm-agents 6
ec2-deployment-dashboard 6
fortify-on-demand-uploader 6
ghprb 6
gitlab-oauth 6
gitlab-plugin 6
pipeline-maven 6
repository-connector 6
aws-codecommit-trigger 5
codedx 5
credentials 5
delphix 5
extended-choice-parameter 5
Quick Filters