org.jenkins-ci.plugins

1,024 tracked vulnerabilities.

CVE-2019-10349 MEDIUM
Jenkins Dependency Graph Viewer Plugin < 0.13 - Stored Cross-Site Scripting
Jul 11, 2019
CVSS 5.4
EPSS 0.01
CVE-2019-10348 HIGH
Jenkins Gogs Plugin < 1.0.14 - Cleartext Storage of Sensitive Information in Job Config Files
Jul 11, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10339 HIGH
Jenkins JX Resources Plugin <= 1.0.36 - Missing Authorization in GlobalPluginConfiguration
Jun 11, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10338 HIGH
Jenkins JX Resources Plugin < 1.0.36 - Cross-Site Request Forgery via GlobalPluginConfiguration#doValidateClient
Jun 11, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10337 HIGH
Jenkins Token Macro Plugin < 2.7 - XML External Entity Injection via XML Macro
Jun 11, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-10336 MEDIUM
Jenkins ElectricFlow < 1.1.6 - Cross-Site Scripting via Post-Build Step Configuration
Jun 11, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-10335 MEDIUM
Jenkins ElectricFlow < 1.1.6 - Stored Cross-Site Scripting via Build Status Page
Jun 11, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-10334 MEDIUM
Jenkins ElectricFlow < 1.1.5 - SSL/TLS and Hostname Verification Disabled via MultipartUtility.java
Jun 11, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10333 MEDIUM
Jenkins ElectricFlow < 1.1.5 - Missing Authorization in HTTP Endpoints
Jun 11, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10332 MEDIUM
Jenkins ElectricFlow < 1.1.5 - Missing Authorization in Configuration Connection Test
Jun 11, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10331 MEDIUM
Jenkins ElectricFlow < 1.1.5 - Cross-Site Request Forgery via Configuration Test Connection
Jun 11, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10330 HIGH
Jenkins Gitea Plugin <= 1.1.1 - Missing Authorization for Jenkinsfile Changes
May 31, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-10329 HIGH
Jenkins InfluxDB Plugin <= 1.21 - Insufficiently Protected Credentials
May 31, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10328 CRITICAL
Jenkins Pipeline Remote Loader Plugin <1.4 - Code Injection
May 31, 2019
CVSS 9.9
EPSS 0.00
CVE-2019-10327 HIGH
Jenkins Pipeline Maven Integration Plugin < 1.7.0 - XML External Entity Injection via Malicious XML File
May 31, 2019
CVSS 8.1
EPSS 0.00
CVE-2019-10324 MEDIUM
Jenkins Artifactory Plugin < 3.2.3 - Cross-Site Request Forgery in Release and Staging Actions
May 31, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-10323 MEDIUM
Jenkins Artifactory Plugin <= 3.2.3 - Missing Authorization in fillCredentialsIdItems Methods
May 31, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10322 MEDIUM
Jenkins Artifactory Plugin <= 3.2.2 - Missing Authorization in Test Connection Feature
May 31, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10321 MEDIUM
Jenkins Artifactory Plugin <= 3.2.2 - Cross-Site Request Forgery via Test Connection
May 31, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10320 MEDIUM
Jenkins Credentials Plugin <2.1.18 - Info Disclosure
May 21, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-10318 HIGH
Jenkins Azure AD Plugin <= 0.3.3 - Insufficiently Protected Credentials in Global Configuration
Apr 30, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10316 HIGH
Jenkins Aqua MicroScanner Plugin <= 1.0.5 - Insufficiently Protected Credentials
Apr 30, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10315 HIGH
Jenkins GitHub Authentication Plugin < 0.31 - Cross-Site Request Forgery via OAuth State Parameter
Apr 30, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-10314 MEDIUM
Jenkins Koji Plugin < 0.3 - Improper Certificate Validation
Apr 30, 2019
CVSS 5.9
EPSS 0.00
CVE-2019-10313 HIGH
Jenkins Twitter Plugin < 0.7 - Insufficiently Protected Credentials
Apr 30, 2019
CVSS 8.8
EPSS 0.00