2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-1000094Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one th...
CVE-2017-1000093Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request For...
CVE-2017-1000092Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to ...
CVE-2017-1000091GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validat...
CVE-2017-1000090Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself ...
CVE-2017-1000089Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact wit...
CVE-2017-1000088The Sidebar Link plugin allows users able to configure jobs, views, and agents to add entries to the sidebar of these ob...
CVE-2017-1000087GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one the...
CVE-2017-1000086The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change i...
CVE-2017-1000085Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list...
CVE-2017-1000084Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the bu...
CVE-2017-1000077Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d...
CVE-2017-1000076Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d...
CVE-2017-12149CRITICAL9.8In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter ...
CVE-2017-9792In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any...
CVE-2017-8048In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to...
CVE-2017-8047In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in som...
CVE-2017-1541A flaw in the AIX 5.3, 6.1, 7.1, and 7.2 JRE/SDK installp and updatep packages prevented the java.security, java.policy ...
CVE-2017-15011The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and all...
CVE-2017-15010A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An at...
CVE-2017-15009PRTG Network Monitor version 17.3.33.2830 is vulnerable to reflected Cross-Site Scripting on error.htm (the error page),...
CVE-2017-15008PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all sensor titles, related to ...
CVE-2017-14997GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an i...
CVE-2017-14995The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server ...
CVE-2017-14994ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now