Skip to main content

Vendor archive

jenkins CVEs

Beta · best-effort

1,797 CVEs tagged to vendor jenkins78 Critical, 476 High, 1,209 Medium, 34 Low, 0 Unrated.

CVE-2018-1000608

Published Jun 26, 2018

A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker with local file system access…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000607

Published Jun 26, 2018

A arbitrary file write vulnerability exists in Jenkins Fortify CloudScan Plugin 1.5.1 and earlier in ArchiveUtil.java that allows attackers able to control rulepack zip file conte…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000606

Published Jun 26, 2018

A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overall/Read access to cause Jenkins…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000605

Published Jun 26, 2018

A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidator.java that allows attackers…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000604

Published Jun 26, 2018

A persisted cross-site scripting vulnerability exists in Jenkins Badge Plugin 1.4 and earlier in BadgeSummaryAction.java, HtmlBadgeAction.java that allows attackers able to contro…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000603

Published Jun 26, 2018

A exposure of sensitive information vulnerability exists in Jenkins Openstack Cloud Plugin 2.35 and earlier in BootSource.java, InstancesToRun.java, JCloudsCleanupThread.java, JCl…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000602

Published Jun 26, 2018

A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000601

Published Jun 26, 2018

A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the p…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000600

Published Jun 26, 2018

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-spe…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-1000202

Published Jun 5, 2018

A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000198

Published Jun 5, 2018

A XML external entity processing vulnerability exists in Jenkins Black Duck Hub Plugin 3.1.0 and older in PostBuildScanDescriptor.java that allows attackers with Overall/Read perm…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000197

Published Jun 5, 2018

An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to r…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000196

Published Jun 5, 2018

A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifier.rb, views/gitlab_notifier/global.erb that allows attacker…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000191

Published Jun 5, 2018

A exposure of sensitive information vulnerability exists in Jenkins Black Duck Detect Plugin 1.4.0 and older in DetectPostBuildStepDescriptor.java that allows attackers with Overa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000190

Published Jun 5, 2018

A exposure of sensitive information vulnerability exists in Jenkins Black Duck Hub Plugin 4.0.0 and older in PostBuildScanDescriptor.java that allows attackers with Overall/Read a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000189

Published Jun 5, 2018

A command execution vulnerability exists in Jenkins Absint Astree Plugin 1.0.5 and older in AstreeBuilder.java that allows attackers with Overall/Read access to execute a command…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000188

Published Jun 5, 2018

A server-side request forgery vulnerability exists in Jenkins CAS Plugin 1.4.1 and older in CasSecurityRealm.java that allows attackers with Overall/Read access to cause Jenkins t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000187

Published Jun 5, 2018

A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive variables such as pa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000186

Published Jun 5, 2018

A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000185

Published Jun 5, 2018

A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000184

Published Jun 5, 2018

A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Overall/Read access to cause Jen…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,576-1,600 of 1,797 CVEsPage 64 of 72