org.jenkins-ci.plugins

1,024 tracked vulnerabilities.

CVE-2017-1000109 MEDIUM
OWASP Dependency-Check Plugin - XSS
Oct 05, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-1000108 HIGH
Pipeline: Input Step Plugin - Info Disclosure
Oct 05, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-1000107 HIGH
Script Security Plugin - Code Injection
Oct 05, 2017
CVSS 8.8
EPSS 0.00
CVE-2017-1000104 MEDIUM
Config File Provider Plugin < 2.16.1 - Unauthenticated Sensitive File Access
Oct 05, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-1000095 MEDIUM
Jenkins Script Security < 1.29.1 - Sandbox Bypass via DefaultGroovyMethods Whitelist
Oct 05, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-1000094 MEDIUM
Docker Commons Plugin - Info Disclosure
Oct 05, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-1000093 HIGH
Poll SCM Plugin < 1.3.1 - Cross-Site Request Forgery via API
Oct 05, 2017
CVSS 8.8
EPSS 0.00
CVE-2017-1000092 HIGH
Jenkins Git Plugin - Cross-Site Request Forgery via Form Validation
Oct 05, 2017
CVSS 7.5
EPSS 0.00
CVE-2017-1000091 MEDIUM
GitHub Branch Source Plugin - Cross-Site Request Forgery via Form Validation
Oct 05, 2017
CVSS 6.3
EPSS 0.00
CVE-2017-1000090 HIGH
Role-based Authorization Strategy Plugin - CSRF
Oct 05, 2017
CVSS 8.8
EPSS 0.00
CVE-2017-1000089 MEDIUM
Jenkins Pipeline < 2.5 and pipeline-build-step < 2.5.1 - Unauthenticated Arbitrary Project Triggering
Oct 05, 2017
CVSS 5.3
EPSS 0.00
CVE-2017-1000088 MEDIUM
Sidebar Link Plugin < 1.8 - Stored Cross-Site Scripting via Sidebar Link Configuration
Oct 05, 2017
CVSS 5.4
EPSS 0.00
CVE-2017-1000087 MEDIUM
GitHub Branch Source - Info Disclosure
Oct 05, 2017
CVSS 4.3
EPSS 0.00
CVE-2017-1000086 HIGH
Periodic Backup Plugin - Privilege Escalation & CSRF
Oct 05, 2017
CVSS 8.0
EPSS 0.00
CVE-2017-1000085 MEDIUM
Subversion Plugin - Info Disclosure
Oct 05, 2017
CVSS 6.5
EPSS 0.00
CVE-2017-1000084 MEDIUM
Jenkins Parameterized Trigger Plugin - Unauthenticated Arbitrary Project Triggering
Oct 05, 2017
CVSS 6.5
EPSS 0.00
CVE-2016-3102 HIGH
Jenkins Script Security Plugin < 1.18.1 - Sandbox Bypass via Direct Field Access or Array Operations
Feb 09, 2017
CVSS 7.3
EPSS 0.00
CVE-2016-3101 MEDIUM
Jenkins Extra Columns < 1.17 - Cross-Site Scripting via Unfiltered Tooltip Markup
Feb 09, 2017
CVSS 5.4
EPSS 0.00
CVE-2015-5298 MEDIUM
Google Login Plugin <1.2 - Auth Bypass
Jul 07, 2022
CVSS 6.5
EPSS 0.00
CVE-2013-6372
Jenkins Subversion Plugin < 1.54 - Credential Disclosure via Base64-Encoded Storage
May 08, 2014
EPSS 0.00
CVE-2013-5676
Jenkins Plugin for SonarQube <= 3.7 - Authenticated Cleartext Password Exposure via sonar.sonarPassword Parameter
Dec 13, 2013
EPSS 0.05
CVE-2013-6373
Jenkins Exclusion Plugin < 0.9 - Authenticated Resource Lock Bypass
Nov 25, 2013
EPSS 0.00
CVE-2012-4441 MEDIUM
Jenkins < 1.482 and LTS < 1.466.2 - Cross-Site Scripting in CI Game Plugin
Nov 18, 2019
CVSS 6.1
EPSS 0.02
CVE-2012-4440 MEDIUM
Jenkins < 1.482 and LTS < 1.466.2 - Cross-Site Scripting in Violations Plugin
Nov 18, 2019
CVSS 6.1
EPSS 0.02