Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2019-03-28 CVE-2019-1003048 Missing Encryption of Sensitive Data vulnerability in Jenkins Prqa
A vulnerability in Jenkins PRQA Plugin 3.1.0 and earlier allows attackers with local file system access to the Jenkins home directory to obtain the unencrypted password from the plugin configuration.
local
low complexity
jenkins CWE-311
7.8
2019-03-28 CVE-2019-1003047 Missing Authorization vulnerability in Jenkins Fortify on Demand Uploader
A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-862
6.5
2019-03-28 CVE-2019-1003046 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Fortify on Demand Uploader
A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers to initiate a connection to an attacker-specified server.
network
low complexity
jenkins CWE-352
6.5
2019-03-28 CVE-2019-1003044 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Slack Notification
A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
high complexity
jenkins CWE-352
7.1
2019-03-28 CVE-2019-1003043 Missing Authorization vulnerability in Jenkins Slack Notification
A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
high complexity
jenkins CWE-862
7.5
2019-03-28 CVE-2019-1003042 Cross-site Scripting vulnerability in Jenkins Lockable Resources
A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to control resource names to inject arbitrary JavaScript in web pages rendered by the plugin.
network
low complexity
jenkins CWE-79
5.4
2019-03-28 CVE-2019-1003041 Unsafe Reflection vulnerability in multiple products
A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.
network
low complexity
jenkins redhat CWE-470
critical
9.8
2019-03-28 CVE-2019-1003040 Unsafe Reflection vulnerability in multiple products
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.
network
low complexity
jenkins redhat CWE-470
critical
9.8
2019-03-08 CVE-2019-1003039 Insufficiently Protected Credentials vulnerability in Jenkins Appdynamics
An insufficiently protected credentials vulnerability exists in JenkinsAppDynamics Dashboard Plugin 1.0.14 and earlier in src/main/java/nl/codecentric/jenkins/appd/AppDynamicsResultsPublisher.java that allows attackers without permission to obtain passwords configured in jobs to obtain them.
network
low complexity
jenkins CWE-522
8.8
2019-03-08 CVE-2019-1003038 Insufficiently Protected Credentials vulnerability in Jenkins Repository Connector
An insufficiently protected credentials vulnerability exists in Jenkins Repository Connector Plugin 1.2.4 and earlier in src/main/java/org/jvnet/hudson/plugins/repositoryconnector/ArtifactDeployer.java, src/main/java/org/jvnet/hudson/plugins/repositoryconnector/Repository.java, src/main/java/org/jvnet/hudson/plugins/repositoryconnector/UserPwd.java that allows an attacker with local file system access or control of a Jenkins administrator's web browser (e.g.
local
low complexity
jenkins CWE-522
7.8