VYPR

Vendor CVEs

Jenkins Project

All CVEs

1,869 total · sorted by risk
  • CVE-2020-2153MedMar 9, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins Backlog Plugin 2.4 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.

  • CVE-2020-2148MedMar 9, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.

  • CVE-2020-2147MedMar 9, 2020
    risk 0.21cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Mac Plugin 1.1.0 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.

  • CVE-2020-2142MedMar 9, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins P4 Plugin 1.10.10 and earlier allows attackers with Overall/Read permission to trigger builds.

  • CVE-2020-2141MedMar 9, 2020
    risk 0.21cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins P4 Plugin 1.10.10 and earlier allows attackers to trigger builds or add a labels in Perforce.

  • CVE-2020-2126MedFeb 12, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins master where it can be viewed by users with access to the master file system.

  • CVE-2020-2104MedJan 29, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.

  • CVE-2020-2095MedJan 15, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins Redgate SQL Change Automation Plugin 2.0.4 and earlier stored an API key unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2020-2094MedJan 15, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient.

  • CVE-2019-16554MedDec 17, 2019
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Read permission to have Jenkins evaluate a computationally expensive regular expression.

  • CVE-2019-16547MedNov 21, 2019
    risk 0.21cvss 4.3epss 0.01

    Missing permission checks in various API endpoints in Jenkins Google Compute Engine Plugin 4.1.1 and earlier allow attackers with Overall/Read permission to obtain limited information about the plugin configuration and environment.

  • CVE-2019-10474MedOct 23, 2019
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Global Post Script Plugin in allowed users with Overall/Read access to list the scripts available to the plugin stored on the Jenkins master file system.

  • CVE-2019-10473MedOct 23, 2019
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Libvirt Slaves Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2019-10455MedOct 16, 2019
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Rundeck Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2019-10454MedOct 16, 2019
    risk 0.21cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Rundeck Plugin allows attackers to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2019-10450LowOct 16, 2019
    risk 0.21cvss 3.3epss 0.00

    Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10442MedOct 16, 2019
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2019-10441MedOct 16, 2019
    risk 0.21cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2019-10439MedOct 16, 2019
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier in various 'doFillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2019-10357MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by global libraries.

  • CVE-2019-10344MedJul 31, 2019
    risk 0.21cvss 4.3epss 0.01

    Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema and documentation for this plugin containing detailed information about installed plugins.

  • CVE-2019-10354MedJul 17, 2019
    risk 0.21cvss 4.3epss 0.02

    A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.

  • CVE-2019-10320MedMay 21, 2019
    risk 0.21cvss 4.3epss 0.01

    Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path, and obtain the certificate content of files containing a PKCS#12 certificate.

  • CVE-2019-1003036MedMar 8, 2019
    risk 0.21cvss 4.3epss 0.01

    A data modification vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgent.java that allows attackers with Overall/Read permission to attach a public IP address to an Azure VM agent.

  • CVE-2019-1003035MedMar 8, 2019
    risk 0.21cvss 4.3epss 0.01

    An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/microsoft/azure/vmagent/AzureVMAgentTemplate.java, src/main/java/com/microsoft/azure/vmagent/AzureVMCloud.java that allows attackers with Overall/Read permission…

  • CVE-2019-1003030CriKEVMar 8, 2019
    risk 0.21cvss 9.9epss 0.76

    A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.

  • CVE-2019-1003029CriKEVMar 8, 2019
    risk 0.21cvss 9.9epss 0.74

    A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows…

  • CVE-2019-1003018MedFeb 6, 2019
    risk 0.21cvss 4.3epss 0.01

    An exposure of sensitive information vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm/config.jelly that allows attackers able to view a Jenkins administrator's web browser output, or control the browser (e.g. malicious…

  • CVE-2019-1003010MedFeb 6, 2019
    risk 0.21cvss 4.3epss 0.01

    A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.

  • CVE-2018-1000862MedDec 10, 2018
    risk 0.21cvss 4.3epss 0.01

    An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build…

  • CVE-2018-1999046MedAug 23, 2018
    risk 0.21cvss 4.3epss 0.01

    A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.java that allows attackers With Overall/Read permission to access the connection log for any agent.

  • CVE-2018-1999037MedAug 1, 2018
    risk 0.21cvss 4.3epss 0.01

    A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.java that allows attackers to stop tracking a resource.

  • CVE-2018-1999006MedJul 23, 2018
    risk 0.21cvss 4.3epss 0.01

    A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of the most recent…

  • CVE-2018-1999004MedJul 23, 2018
    risk 0.21cvss 4.3epss 0.01

    A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches.

  • CVE-2018-1999003MedJul 23, 2018
    risk 0.21cvss 4.3epss 0.01

    A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.

  • CVE-2018-1000402MedJul 9, 2018
    risk 0.21cvss 4.3epss 0.01

    Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposure vulnerability in AWSCodeDeployPublisher.java that can result in Disclosure of environment variables. This vulnerability appears to have been fixed in 1.20…

  • CVE-2018-1000195MedJun 5, 2018
    risk 0.21cvss 4.3epss 0.02

    A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn whether the response is…

  • CVE-2018-1000193MedJun 5, 2018
    risk 0.21cvss 4.3epss 0.01

    A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as…

  • CVE-2018-1000192MedJun 5, 2018
    risk 0.21cvss 4.3epss 0.01

    A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.

  • CVE-2018-1000185MedJun 5, 2018
    risk 0.21cvss 4.3epss 0.01

    A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.

  • CVE-2017-2598MedMay 23, 2018
    risk 0.21cvss 4.3epss 0.01

    Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).

  • CVE-2017-2609MedMay 22, 2018
    risk 0.21cvss 4.3epss 0.02

    jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autocomplete feature on the search box discloses the names of the views in its suggestions, including the ones for which the current user does…

  • CVE-2017-2604MedMay 15, 2018
    risk 0.21cvss 4.3epss 0.01

    In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not being consistently protected by permission checks (SECURITY-371).

  • CVE-2017-2600MedMay 15, 2018
    risk 0.21cvss 4.3epss 0.01

    In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of these nodes (SECURITY-343).

  • CVE-2017-2606MedMay 8, 2018
    risk 0.21cvss 4.3epss 0.02

    Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that should not be visible (SECURITY-380). This only affects anonymous users (other users legitimately have access) that were able to get a list of…

  • CVE-2017-2611MedMay 8, 2018
    risk 0.21cvss 4.3epss 0.02

    Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins to trigger these…

  • CVE-2018-1000150LowApr 5, 2018
    risk 0.21cvss 3.3epss 0.00

    An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users.

  • CVE-2018-1000109MedMar 13, 2018
    risk 0.21cvss 4.3epss 0.01

    An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs.

  • CVE-2018-1000105MedMar 13, 2018
    risk 0.21cvss 4.3epss 0.01

    An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to retrieve some configuration information about Gerrit in Jenkins.

  • CVE-2018-1000057MedFeb 9, 2018
    risk 0.21cvss 4.3epss 0.01

    Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to…

Page 34 of 38