Skip to main content

Vendor archive

jenkins CVEs

Beta · best-effort

1,797 CVEs tagged to vendor jenkins78 Critical, 476 High, 1,209 Medium, 34 Low, 0 Unrated.

CVE-2018-1999031

Published Aug 1, 2018

An exposure of sensitive information vulnerability exists in Jenkins meliora-testlab Plugin 1.14 and earlier in TestlabNotifier.java that allows attackers with file system access…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1999029

Published Aug 1, 2018

A cross-site scripting vulnerability exists in Jenkins Shelve Project Plugin 1.5 and earlier in ShelveProjectAction/index.jelly, ShelvedProjectsAction/index.jelly that allows atta…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1999028

Published Aug 1, 2018

An exposure of sensitive information vulnerability exists in Jenkins Accurev Plugin 0.7.16 and earlier in AccurevSCM.java that allows attackers to capture credentials with a known…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1999027

Published Aug 1, 2018

An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that allows attackers to capture c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1999026

Published Aug 1, 2018

A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers to have Jenkins send HTTP requ…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1999025

Published Aug 1, 2018

A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows attackers to impersonate any se…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2652

Published Jul 27, 2018

It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2650

Published Jul 27, 2018

It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access, as well as users with e.g. J…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2649

Published Jul 27, 2018

It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-M…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2648

Published Jul 27, 2018

It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2651

Published Jul 27, 2018

jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the cha…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1999006

Published Jul 23, 2018

A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000404

Published Jul 9, 2018

Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFactory.java, CodeBuilder.java that…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000403

Published Jul 9, 2018

Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000402

Published Jul 9, 2018

Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposure vulnerability in AWSCodeDeployPublisher.java that can res…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000401

Published Jul 9, 2018

Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipelineSCM.java that can result i…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000610

Published Jun 26, 2018

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigura…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000609

Published Jun 26, 2018

A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,551-1,575 of 1,797 CVEsPage 63 of 72