Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Jenkins Subscribe
Total 1395 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-2170 1 Jenkins 1 Rapiddeploy 2020-03-27 3.5 LOW 5.4 MEDIUM
Jenkins RapidDeploy Plugin 4.2 and earlier does not escape package names in the table of packages obtained from a remote server, resulting in a stored XSS vulnerability.
CVE-2020-2163 1 Jenkins 1 Jenkins 2020-03-27 3.5 LOW 5.4 MEDIUM
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerability exploitable by users able to control column headers.
CVE-2020-2162 1 Jenkins 1 Jenkins 2020-03-27 3.5 LOW 5.4 MEDIUM
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.
CVE-2020-2105 1 Jenkins 1 Jenkins 2020-03-16 4.3 MEDIUM 5.4 MEDIUM
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
CVE-2020-2102 1 Jenkins 1 Jenkins 2020-03-16 3.5 LOW 5.3 MEDIUM
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
CVE-2020-2103 1 Jenkins 1 Jenkins 2020-03-16 4.0 MEDIUM 5.4 MEDIUM
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
CVE-2020-2104 1 Jenkins 1 Jenkins 2020-03-16 4.0 MEDIUM 4.3 MEDIUM
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.
CVE-2020-2099 1 Jenkins 1 Jenkins 2020-03-16 7.5 HIGH 8.6 HIGH
Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.
CVE-2020-2100 1 Jenkins 1 Jenkins 2020-03-16 5.0 MEDIUM 5.8 MEDIUM
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848.
CVE-2020-2101 1 Jenkins 1 Jenkins 2020-03-16 3.5 LOW 5.3 MEDIUM
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.
CVE-2020-2153 1 Jenkins 1 Backlog 2020-03-11 4.0 MEDIUM 4.3 MEDIUM
Jenkins Backlog Plugin 2.4 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
CVE-2020-2144 1 Jenkins 1 Rundeck 2020-03-10 5.5 MEDIUM 7.1 HIGH
Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2145 1 Jenkins 1 Zephyr Enterprise Test Management 2020-03-10 2.1 LOW 5.5 MEDIUM
Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system.
CVE-2020-2134 1 Jenkins 1 Script Security 2020-03-10 6.5 MEDIUM 8.8 HIGH
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor bodies.
CVE-2020-2135 1 Jenkins 1 Script Security 2020-03-10 6.5 MEDIUM 8.8 HIGH
Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable.
CVE-2020-2138 1 Jenkins 1 Cobertura 2020-03-10 5.5 MEDIUM 7.1 HIGH
Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2136 1 Jenkins 1 Git 2020-03-09 3.5 LOW 5.4 MEDIUM
Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.
CVE-2020-2158 1 Jenkins 1 Literate 2020-03-09 6.5 MEDIUM 8.8 HIGH
Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
CVE-2020-2148 1 Jenkins 1 Mac 2020-03-09 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.
CVE-2020-2147 1 Jenkins 1 Mac 2020-03-09 4.3 MEDIUM 4.3 MEDIUM
A cross-site request forgery vulnerability in Jenkins Mac Plugin 1.1.0 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.