Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2020-03-09 CVE-2020-2159 OS Command Injection vulnerability in Jenkins Cryptomove
Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the OS user account running Jenkins.
network
low complexity
jenkins CWE-78
8.8
2020-03-09 CVE-2020-2158 Deserialization of Untrusted Data vulnerability in Jenkins Literate 0.1/0.2/1.0
Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
network
low complexity
jenkins CWE-502
8.8
2020-03-09 CVE-2020-2157 Cleartext Transmission of Sensitive Information vulnerability in Jenkins Skytap Cloud CI
Jenkins Skytap Cloud CI Plugin 2.07 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
network
low complexity
jenkins CWE-319
4.3
2020-03-09 CVE-2020-2156 Cleartext Transmission of Sensitive Information vulnerability in Jenkins Deployhub
Jenkins DeployHub Plugin 8.0.14 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
network
low complexity
jenkins CWE-319
4.3
2020-03-09 CVE-2020-2155 Cleartext Transmission of Sensitive Information vulnerability in Jenkins Openshift Deployer
Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
network
low complexity
jenkins CWE-319
5.3
2020-03-09 CVE-2020-2154 Cleartext Storage of Sensitive Information vulnerability in Jenkins Zephyr for Jira Test Management
Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configuration file on the Jenkins master file system.
local
low complexity
jenkins CWE-312
5.5
2020-03-09 CVE-2020-2153 Cleartext Transmission of Sensitive Information vulnerability in Jenkins Backlog
Jenkins Backlog Plugin 2.4 and earlier transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
network
low complexity
jenkins CWE-319
4.3
2020-03-09 CVE-2020-2152 Cross-site Scripting vulnerability in Jenkins Subversion Release Manager
Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.
network
low complexity
jenkins CWE-79
6.1
2020-03-09 CVE-2020-2151 Cleartext Transmission of Sensitive Information vulnerability in Jenkins Quality Gates
Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
network
low complexity
jenkins CWE-319
5.3
2020-03-09 CVE-2020-2150 Cleartext Transmission of Sensitive Information vulnerability in Jenkins Sonar Quality Gates
Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
network
low complexity
jenkins CWE-319
5.3