Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2018-07-09 CVE-2018-1000404 Insufficiently Protected Credentials vulnerability in Jenkins AWS Codebuild
Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFactory.java, CodeBuilder.java that can result in Credentials Disclosure.
local
low complexity
jenkins CWE-522
7.8
2018-07-09 CVE-2018-1000403 Insufficiently Protected Credentials vulnerability in Jenkins AWS Codedeploy
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result in Credentials Disclosure.
local
low complexity
jenkins CWE-522
7.8
2018-07-09 CVE-2018-1000402 Information Exposure vulnerability in Jenkins AWS Codedeploy
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposure vulnerability in AWSCodeDeployPublisher.java that can result in Disclosure of environment variables.
network
low complexity
jenkins CWE-200
4.3
2018-07-09 CVE-2018-1000401 Insufficiently Protected Credentials vulnerability in Jenkins AWS Codepipeline
Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipelineSCM.java that can result in Credentials Disclosure.
local
low complexity
jenkins CWE-522
7.8
2018-06-26 CVE-2018-1000610 Insufficiently Protected Credentials vulnerability in Jenkins Configuration AS Code
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that allows attackers with access to Jenkins log files to obtain the passwords configured using Configuration as Code Plugin.
network
low complexity
jenkins CWE-522
8.8
2018-06-26 CVE-2018-1000609 Information Exposure vulnerability in Jenkins Configuration AS Code
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overall/Read access to obtain the YAML export of the Jenkins configuration.
network
low complexity
jenkins CWE-200
6.5
2018-06-26 CVE-2018-1000608 Insufficiently Protected Credentials vulnerability in Jenkins Z/Os Connector
A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker with local file system access or control of a Jenkins administrator's web browser (e.g.
network
low complexity
jenkins CWE-522
7.2
2018-06-26 CVE-2018-1000607 Improper Input Validation vulnerability in Jenkins Fortify Cloudscan
A arbitrary file write vulnerability exists in Jenkins Fortify CloudScan Plugin 1.5.1 and earlier in ArchiveUtil.java that allows attackers able to control rulepack zip file contents to overwrite any file on the Jenkins master file system, only limited by the permissions of the user the Jenkins master process is running as.
network
low complexity
jenkins CWE-20
6.5
2018-06-26 CVE-2018-1000606 Server-Side Request Forgery (SSRF) vulnerability in Jenkins Urltrigger
A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
network
low complexity
jenkins CWE-918
6.5
2018-06-26 CVE-2018-1000605 Improper Certificate Validation vulnerability in Jenkins Collabnet
A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidator.java that allows attackers to impersonate any service that Jenkins connects to.
network
high complexity
jenkins CWE-295
7.4