Filter
AND
-Infinity
0

JenkinsJenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed …

EPSS
0.03%
First published (updated )

Jenkins Stack HammerJenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config…

EPSS
0.03%
First published (updated )

JenkinsJenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in jo…

EPSS
0.03%
First published (updated )

Jenkins Monitor Remote JobJenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Je…

EPSS
0.03%
First published (updated )

Cadence vManager PluginJenkins Cadence vManager Plugin 4.0.0-282.v5096a_c2db_275 and earlier stores Verisium Manager vAPI k…

EPSS
0.03%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Jenkins Simple QueueCSRF

EPSS
0.02%
First published (updated )

Jenkins LTSA missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers wi…

EPSS
0.03%
First published (updated )

Jenkins LTSA missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers wi…

EPSS
0.03%
First published (updated )

maven/org.jenkins-ci.main:jenkins-coreIn Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) chara…

EPSS
0.03%
First published (updated )

maven/org.jenkins-ci.main:jenkins-coreCSRF

EPSS
0.02%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

maven/org.jenkins-ci.main:jenkins-coreJenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when …

EPSS
0.01%
First published (updated )

maven/org.jenkins-ci.main:jenkins-coreJenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when …

EPSS
0.01%
First published (updated )

Jenkins Azure Service Fabric PluginA missing permission check in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers w…

EPSS
0.04%
First published (updated )

Jenkins Folder-based Authorization Strategy PluginJenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify th…

EPSS
0.04%
First published (updated )

Jenkins Azure Service Fabric PluginCSRF

EPSS
0.04%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Jenkins Eiffel Broadcaster PluginJenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as th…

EPSS
0.04%
First published (updated )

maven/org.jenkins-ci.plugins:gitlab-pluginAn incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with globa…

EPSS
0.04%
First published (updated )

Jenkins Script SecurityJenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ a…

First published (updated )

maven/org.jenkins-ci.main:jenkins-coreIf an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLe…

First published (updated )

maven/org.jenkins-ci.main:jenkins-coreJenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

maven/org.jenkins-ci.main:jenkins-coreJenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP en…

First published (updated )

maven/org.jenkins-ci.plugins:build-monitor-pluginXSS

EPSS
0.04%
First published (updated )

maven/com.rapid7:jenkinsci-appspider-pluginJenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpo…

EPSS
0.04%
First published (updated )

maven/com.sonymobile.jenkins.plugins.mq:mq-notifierJenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of …

EPSS
0.04%
First published (updated )

maven/io.jenkins.plugins:gitlab-branch-sourceCSRF

EPSS
0.05%
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

maven/io.jenkins.plugins:gitlab-branch-sourceJenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time compari…

EPSS
0.05%
First published (updated )

maven/io.jenkins.plugins:gitlab-branch-sourceInfoleak

EPSS
0.05%
First published (updated )

maven/org.jenkins-ci.plugins:matrix-projectPath Traversal

EPSS
0.04%
First published (updated )

maven/com.cloudtp.jenkins:paaslane-estimateMissing permission checks in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allow attackers with…

First published (updated )

maven/com.cloudtp.jenkins:paaslane-estimateJenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens disp…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203