Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2019-10-16 CVE-2019-10452 Cleartext Storage of Sensitive Information vulnerability in Jenkins View26 Test-Reporting
Jenkins View26 Test-Reporting Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-312
4.3
2019-10-16 CVE-2019-10451 Cleartext Storage of Sensitive Information vulnerability in Jenkins Soasta Cloudtest
Jenkins SOASTA CloudTest Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-312
4.3
2019-10-16 CVE-2019-10450 Cleartext Storage of Sensitive Information vulnerability in Jenkins Elasticbox CI
Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
local
low complexity
jenkins CWE-312
3.3
2019-10-16 CVE-2019-10449 Cleartext Storage of Sensitive Information vulnerability in Jenkins Fortify on Demand
Jenkins Fortify on Demand Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-312
8.8
2019-10-16 CVE-2019-10448 Insufficiently Protected Credentials vulnerability in Jenkins Extensive Testing 1.4.3/1.4.4
Jenkins Extensive Testing Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
8.8
2019-10-16 CVE-2019-10447 Cleartext Storage of Sensitive Information vulnerability in Jenkins Sofy.Ai 1.0.0/1.0.1/1.0.3
Jenkins Sofy.AI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-312
4.3
2019-10-16 CVE-2019-10446 Improper Certificate Validation vulnerability in Jenkins Cadence Vmanager
Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.
network
low complexity
jenkins CWE-295
8.2
2019-10-16 CVE-2019-10445 Missing Authorization vulnerability in Jenkins Google Kubernetes Engine
A missing permission check in Jenkins Google Kubernetes Engine Plugin 0.7.0 and earlier allowed attackers with Overall/Read permission to obtain limited information about the scope of a credential with an attacker-specified credentials ID.
network
low complexity
jenkins CWE-862
4.3
2019-10-16 CVE-2019-10444 Improper Certificate Validation vulnerability in Jenkins Bumblebee HP ALM
Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connections to HP ALM.
network
low complexity
jenkins CWE-295
6.5
2019-10-16 CVE-2019-10443 Cleartext Storage of Sensitive Information vulnerability in Jenkins Icescrum
Jenkins iceScrum Plugin 1.1.4 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-312
8.8