VYPR

Vendor CVEs

Jenkins Project

All CVEs

1,922 total · sorted by risk
  • CVE-2019-10375MedAug 7, 2019
    risk 0.42cvss 6.5epss 0.01

    An arbitrary file read vulnerability in Jenkins File System SCM Plugin 2.1 and earlier allows attackers able to configure jobs in Jenkins to obtain the contents of any file on the Jenkins master.

  • CVE-2019-10371HigAug 7, 2019
    risk 0.42cvss 7.5epss 0.01

    A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.

  • CVE-2019-10369MedAug 7, 2019
    risk 0.42cvss 6.5epss 0.01

    A missing permission check in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnection and JCloudsCloud.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified…

  • CVE-2019-1010241MedJul 19, 2019
    risk 0.42cvss 6.5epss 0.01

    Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly line #30 (passwordVariable). The attack vector is: Attacker…

  • CVE-2019-10353HigJul 17, 2019
    risk 0.42cvss 7.5epss 0.02

    CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.

  • CVE-2019-10337HigJun 11, 2019
    risk 0.42cvss 7.5epss 0.02

    An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the input file for the "XML" macro to have Jenkins resolve external entities, resulting in the extraction of secrets from the Jenkins…

  • CVE-2019-10330HigMay 31, 2019
    risk 0.42cvss 7.5epss 0.02

    Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to change Jenkinsfiles even if Jenkins is configured to consider them to be untrusted.

  • CVE-2019-10293MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A missing permission check in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-10292MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows attackers to initiate a connection to an attacker-specified server.

  • CVE-2019-10290MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.02

    A missing permission check in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI form validation method allowed attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-10289MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI form validation method allowed attackers to initiate a connection to an attacker-specified server.

  • CVE-2019-10279MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A missing permission check in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-10278MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.

  • CVE-2019-1003097MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.02

    Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-1003096MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.02

    Jenkins TestFairy Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-1003095MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    Jenkins Perfecto Mobile Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-1003094MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    Jenkins Open STF Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-1003091MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A missing permission check in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-1003090MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server.

  • CVE-2019-1003088MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    Jenkins Fabric Beta Publisher Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-1003087MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.02

    A missing permission check in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-1003086MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.

  • CVE-2019-1003083MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A missing permission check in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-1003082MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.

  • CVE-2019-1003081MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.02

    A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-1003080MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers to initiate a connection to an attacker-specified server.

  • CVE-2019-1003079MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.02

    A missing permission check in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-1003078MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.

  • CVE-2019-1003077MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-1003076MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers to initiate a connection to an attacker-specified server.

  • CVE-2019-1003059MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A missing permission check in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-1003058MedApr 4, 2019
    risk 0.42cvss 6.5epss 0.01

    A cross-site request forgery vulnerability in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers to initiate a connection to an attacker-specified server.

  • CVE-2019-1003045MedMar 28, 2019
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, or local file system access to the Jenkins home directory to obtain the API token configured in this plugin's configuration.

  • CVE-2019-1003043HigMar 28, 2019
    risk 0.42cvss 7.5epss 0.01

    A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in…

  • CVE-2019-1003022MedFeb 6, 2019
    risk 0.42cvss 6.5epss 0.01

    A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows attackers to kill threads running on the Jenkins master.

  • CVE-2018-1000421MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-specified credentials IDs obtained…

  • CVE-2018-1000420MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.

  • CVE-2018-1000419MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.02

    An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.

  • CVE-2018-1999047MedAug 23, 2018
    risk 0.42cvss 6.5epss 0.01

    A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.

  • CVE-2018-1999027HigAug 1, 2018
    risk 0.42cvss 7.5epss 0.01

    An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.

  • CVE-2018-1000609MedJun 26, 2018
    risk 0.42cvss 6.5epss 0.01

    A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overall/Read access to obtain the YAML export of the Jenkins configuration.

  • CVE-2018-1000607MedJun 26, 2018
    risk 0.42cvss 6.5epss 0.01

    A arbitrary file write vulnerability exists in Jenkins Fortify CloudScan Plugin 1.5.1 and earlier in ArchiveUtil.java that allows attackers able to control rulepack zip file contents to overwrite any file on the Jenkins master file system, only limited by the permissions of the…

  • CVE-2018-1000198MedJun 5, 2018
    risk 0.42cvss 6.5epss 0.01

    A XML external entity processing vulnerability exists in Jenkins Black Duck Hub Plugin 3.1.0 and older in PostBuildScanDescriptor.java that allows attackers with Overall/Read permission to make Jenkins process XML eternal entities in an XML document.

  • CVE-2018-1000196MedJun 5, 2018
    risk 0.42cvss 6.5epss 0.01

    A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifier.rb, views/gitlab_notifier/global.erb that allows attackers with local Jenkins master file system access or control of a Jenkins administrator's web browser…

  • CVE-2018-1000190MedJun 5, 2018
    risk 0.42cvss 6.5epss 0.01

    A exposure of sensitive information vulnerability exists in Jenkins Black Duck Hub Plugin 4.0.0 and older in PostBuildScanDescriptor.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained…

  • CVE-2018-1000176MedMay 8, 2018
    risk 0.42cvss 6.5epss 0.01

    An exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/emailext/ExtendedEmailPublisher/global.groovy and ExtendedEmailPublisherDescriptor.java that allows attackers with control of a Jenkins…

  • CVE-2018-1000175MedMay 8, 2018
    risk 0.42cvss 6.5epss 0.01

    A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arbitrary files on the Jenkins master.

  • CVE-2018-1000148MedApr 5, 2018
    risk 0.42cvss 6.5epss 0.01

    An exposure of sensitive information vulnerability exists in Jenkins Copy To Slave Plugin version 1.4.4 and older in CopyToSlaveBuildWrapper.java that allows attackers with permission to configure jobs to read arbitrary files from the Jenkins master file system.

  • CVE-2018-1000145MedApr 5, 2018
    risk 0.42cvss 6.5epss 0.01

    An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with local file system access to obtain encrypted Perforce passwords and decrypt them.

  • CVE-2017-1000394HigJan 26, 2018
    risk 0.42cvss 7.5epss 0.01

    Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.

Page 15 of 39