Skip to main content

Vendor/product archive

jenkins / official_owasp_zap CVEs

Beta · best-effort

2 CVEs tagged to jenkins / official_owasp_zap0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-57301

Published Jun 24, 2026

Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-1003060

Published Apr 4, 2019

Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1