Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Jenkins Subscribe
Total 1395 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-2146 1 Jenkins 1 Mac 2020-03-09 5.8 MEDIUM 7.4 HIGH
Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.
CVE-2020-2142 1 Jenkins 1 P4 2020-03-09 4.0 MEDIUM 4.3 MEDIUM
A missing permission check in Jenkins P4 Plugin 1.10.10 and earlier allows attackers with Overall/Read permission to trigger builds.
CVE-2020-2141 1 Jenkins 1 P4 2020-03-09 4.3 MEDIUM 4.3 MEDIUM
A cross-site request forgery vulnerability in Jenkins P4 Plugin 1.10.10 and earlier allows attackers to trigger builds or add a labels in Perforce.
CVE-2020-2139 1 Jenkins 1 Cobertura 2020-03-09 8.5 HIGH 6.5 MEDIUM
An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.
CVE-2020-2137 1 Jenkins 1 Timestamper 2020-03-09 3.5 LOW 4.8 MEDIUM
Jenkins Timestamper Plugin 1.11.1 and earlier does not sanitize HTML formatting of its output, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.
CVE-2020-2154 1 Jenkins 1 Zephyr For Jira Test Management 2020-03-09 2.1 LOW 5.5 MEDIUM
Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configuration file on the Jenkins master file system.
CVE-2020-2140 1 Jenkins 1 Audit Trail 2020-03-09 4.3 MEDIUM 6.1 MEDIUM
Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.
CVE-2020-2155 1 Jenkins 1 Openshift Deployer 2020-03-09 5.0 MEDIUM 5.3 MEDIUM
Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
CVE-2020-2156 1 Jenkins 1 Deployhub 2020-03-09 4.0 MEDIUM 4.3 MEDIUM
Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
CVE-2020-2151 1 Jenkins 1 Quality Gates 2020-03-09 5.0 MEDIUM 5.3 MEDIUM
Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
CVE-2020-2150 1 Jenkins 1 Sonar Quality Gates 2020-03-09 5.0 MEDIUM 5.3 MEDIUM
Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
CVE-2020-2149 1 Jenkins 1 Repository Connector 2020-03-09 5.0 MEDIUM 5.3 MEDIUM
Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
CVE-2020-2157 1 Jenkins 1 Skytap Cloud Ci 2020-03-09 4.0 MEDIUM 4.3 MEDIUM
Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
CVE-2020-2143 1 Jenkins 1 Logstash 2020-03-09 5.0 MEDIUM 5.3 MEDIUM
Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
CVE-2012-0785 2 Cloudbees, Jenkins 2 Jenkins, Jenkins 2020-03-04 7.8 HIGH 7.5 HIGH
Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."
CVE-2020-2122 1 Jenkins 1 Brakeman 2020-02-14 3.5 LOW 5.4 MEDIUM
Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site scripting vulnerability exploitable by users able to control the Brakeman post-build step input data.
CVE-2020-2121 1 Jenkins 1 Google Kubernetes Engine 2020-02-14 6.5 MEDIUM 8.8 HIGH
Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
CVE-2020-2120 1 Jenkins 1 Fitnesse 2020-02-14 6.5 MEDIUM 8.8 HIGH
Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2119 1 Jenkins 1 Azure Ad 2020-02-14 5.0 MEDIUM 5.3 MEDIUM
Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
CVE-2020-2115 1 Jenkins 1 Nunit 2020-02-14 6.5 MEDIUM 8.8 HIGH
Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.