Vulnerabilities
Vulnerable Software
Jenkins:  Security Vulnerabilities
A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allows attackers to add or remove agent labels.
CVSS Score
6.5
EPSS Score
0.006
Published
2020-06-03
Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the parser identifier when rendering charts, resulting in a stored cross-site scripting vulnerability.
CVSS Score
5.4
EPSS Score
0.007
Published
2020-06-03
Jenkins ECharts API Plugin 4.7.0-3 and earlier does not escape the display name of the builds in the trend chart, resulting in a stored cross-site scripting vulnerability.
CVSS Score
5.4
EPSS Score
0.007
Published
2020-06-03
Jenkins Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips, resulting in a stored cross-site scripting vulnerability that can be exploited by users with Job/Configure permission.
CVSS Score
5.4
EPSS Score
0.007
Published
2020-06-03
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps.
CVSS Score
6.5
EPSS Score
0.011
Published
2020-05-06
Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances.
CVSS Score
4.3
EPSS Score
0.009
Published
2020-05-06
Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifacts from jobs they have no permission to access.
CVSS Score
6.5
EPSS Score
0.009
Published
2020-05-06
A cross-site request forgery vulnerability in Jenkins CVS Plugin 2.15 and earlier allows attackers to create and manipulate tags, and to connect to an attacker-specified URL.
CVSS Score
4.3
EPSS Score
0.445
Published
2020-05-06
Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the-middle attacks.
CVSS Score
5.6
EPSS Score
0.007
Published
2020-05-06
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision instances.
CVSS Score
4.3
EPSS Score
0.006
Published
2020-05-06


Contact Us

Shodan ® - All rights reserved