Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2018-08-01 CVE-2018-1999038 Confused Deputy vulnerability in Jenkins Publish Over Cifs
A confused deputy vulnerability exists in Jenkins Publisher Over CIFS Plugin 0.10 and earlier in CifsPublisherPluginDescriptor.java that allows attackers to have Jenkins connect to an attacker specified CIFS server with attacker specified credentials.
network
high complexity
jenkins CWE-441
4.2
2018-08-01 CVE-2018-1999037 Improper Input Validation vulnerability in Jenkins Resource Disposer
A data modification vulnerability exists in Jenkins Resource Disposer Plugin 0.11 and earlier in AsyncResourceDisposer.java that allows attackers to stop tracking a resource.
network
low complexity
jenkins CWE-20
4.3
2018-08-01 CVE-2018-1999036 Information Exposure Through Log Files vulnerability in Jenkins SSH Agent
An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the SSH private key password to users with permission to read the build log.
network
low complexity
jenkins CWE-532
6.5
2018-08-01 CVE-2018-1999035 Improper Certificate Validation vulnerability in Jenkins Inedo Buildmaster 1.0/1.2/1.3
A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java, BuildMasterApi.java that allows attackers to impersonate any service that Jenkins connects to.
network
high complexity
jenkins CWE-295
7.4
2018-08-01 CVE-2018-1999034 Improper Certificate Validation vulnerability in Jenkins Inedo Proget
A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.java that allows attackers to impersonate any service that Jenkins connects to.
network
high complexity
jenkins CWE-295
7.4
2018-08-01 CVE-2018-1999031 Information Exposure vulnerability in Jenkins Meliora Testlab
An exposure of sensitive information vulnerability exists in Jenkins meliora-testlab Plugin 1.14 and earlier in TestlabNotifier.java that allows attackers with file system access to the Jenkins master to obtain the API key stored in this plugin's configuration.
network
low complexity
jenkins CWE-200
6.5
2018-08-01 CVE-2018-1999030 Information Exposure vulnerability in Jenkins Maven Artifact Choicelistprovider (Nexus)
An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and earlier in ArtifactoryChoiceListProvider.java, NexusChoiceListProvider.java, Nexus3ChoiceListProvider.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
network
low complexity
jenkins CWE-200
5.4
2018-08-01 CVE-2018-1999029 Cross-site Scripting vulnerability in Jenkins Shelve Project
A cross-site scripting vulnerability exists in Jenkins Shelve Project Plugin 1.5 and earlier in ShelveProjectAction/index.jelly, ShelvedProjectsAction/index.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
network
low complexity
jenkins CWE-79
5.4
2018-08-01 CVE-2018-1999028 Information Exposure vulnerability in Jenkins Accurev
An exposure of sensitive information vulnerability exists in Jenkins Accurev Plugin 0.7.16 and earlier in AccurevSCM.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
network
low complexity
jenkins CWE-200
8.8
2018-08-01 CVE-2018-1999027 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Saltstack
An exposure of sensitive information vulnerability exists in Jenkins SaltStack Plugin 3.1.6 and earlier in SaltAPIBuilder.java, SaltAPIStep.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
network
high complexity
jenkins CWE-352
7.5