Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2018-06-26 CVE-2018-1000608 Insufficiently Protected Credentials vulnerability in Jenkins Z/Os Connector
A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker with local file system access or control of a Jenkins administrator's web browser (e.g.
network
low complexity
jenkins CWE-522
7.2
2018-06-26 CVE-2018-1000607 Improper Input Validation vulnerability in Jenkins Fortify Cloudscan
A arbitrary file write vulnerability exists in Jenkins Fortify CloudScan Plugin 1.5.1 and earlier in ArchiveUtil.java that allows attackers able to control rulepack zip file contents to overwrite any file on the Jenkins master file system, only limited by the permissions of the user the Jenkins master process is running as.
network
low complexity
jenkins CWE-20
6.5
2018-06-26 CVE-2018-1000606 Server-Side Request Forgery (SSRF) vulnerability in Jenkins Urltrigger
A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.
network
low complexity
jenkins CWE-918
6.5
2018-06-26 CVE-2018-1000605 Improper Certificate Validation vulnerability in Jenkins Collabnet
A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidator.java that allows attackers to impersonate any service that Jenkins connects to.
network
high complexity
jenkins CWE-295
7.4
2018-06-26 CVE-2018-1000604 Cross-site Scripting vulnerability in Jenkins Badge
A persisted cross-site scripting vulnerability exists in Jenkins Badge Plugin 1.4 and earlier in BadgeSummaryAction.java, HtmlBadgeAction.java that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
network
low complexity
jenkins CWE-79
5.4
2018-06-26 CVE-2018-1000603 Information Exposure vulnerability in Jenkins Openstack Cloud
A exposure of sensitive information vulnerability exists in Jenkins Openstack Cloud Plugin 2.35 and earlier in BootSource.java, InstancesToRun.java, JCloudsCleanupThread.java, JCloudsCloud.java, JCloudsComputer.java, JCloudsPreCreationThread.java, JCloudsRetentionStrategy.java, JCloudsSlave.java, JCloudsSlaveTemplate.java, LauncherFactory.java, OpenstackCredentials.java, OpenStackMachineStep.java, SlaveOptions.java, SlaveOptionsDescriptor.java that allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins, and to cause Jenkins to submit HTTP requests to attacker-specified URLs.
network
low complexity
jenkins CWE-200
8.8
2018-06-26 CVE-2018-1000602 Session Fixation vulnerability in Jenkins Saml
A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session.
network
high complexity
jenkins CWE-384
5.9
2018-06-26 CVE-2018-1000601 Information Exposure vulnerability in Jenkins SSH Credentials
A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file system.
network
low complexity
jenkins CWE-200
6.5
2018-06-26 CVE-2018-1000600 Information Exposure vulnerability in Jenkins Github
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-200
8.8
2018-06-05 CVE-2018-1000202 Cross-site Scripting vulnerability in Jenkins Groovy Postbuild
A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge content to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
network
low complexity
jenkins CWE-79
5.4