2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-10422MEDIUM6.5Jenkins Call Remote Job Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they c...
CVE-2019-10421MEDIUM4.3Jenkins Azure Event Grid Build Notifier Plugin stores credentials unencrypted in job config.xml files on the Jenkins mas...
CVE-2019-10420MEDIUM5.5Jenkins Assembla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they...
CVE-2019-10419MEDIUM5.5Jenkins vFabric Application Director Plugin stores credentials unencrypted in its global configuration file on the Jenki...
CVE-2019-10418CRITICAL9.9Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin provides a custom whitelist for script security that allowed a...
CVE-2019-10417CRITICAL9.9Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin provides a custom whitelist for script security that allowed a...
CVE-2019-10416MEDIUM6.5Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on t...
CVE-2019-10415MEDIUM6.5Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration ...
CVE-2019-10414MEDIUM6.5Jenkins Git Changelog Plugin 2.17 and earlier stored credentials unencrypted in job config.xml files on the Jenkins mast...
CVE-2019-10413MEDIUM6.5Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins...
CVE-2019-10412HIGH7.5Jenkins Inedo ProGet Plugin 1.2 and earlier transmitted configured credentials in plain text as part of the global Jenki...
CVE-2019-10411HIGH7.5Jenkins Inedo BuildMaster Plugin 2.4.0 and earlier transmitted configured credentials in plain text as part of the globa...
CVE-2019-10410MEDIUM5.4Jenkins Log Parser Plugin 2.0 and earlier did not escape an error message, resulting in a cross-site scripting vulnerabi...
CVE-2019-10409MEDIUM4.3A missing permission check in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers with Overall/Read p...
CVE-2019-10408MEDIUM4.3A cross-site request forgery vulnerability in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers to ...
CVE-2019-10407MEDIUM6.5Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passed to a build without...
CVE-2019-10406MEDIUM4.8Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global co...
CVE-2019-10405MEDIUM5.4Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/...
CVE-2019-10404MEDIUM5.4Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the reason why a queue items is blcoked in tooltips, r...
CVE-2019-10403MEDIUM5.4Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, r...
CVE-2019-10402MEDIUM5.4In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:combobox form control interpreted its item labels as HTML, ...
CVE-2019-10401MEDIUM5.4In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as H...
CVE-2019-13627MEDIUM6.3It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4...
CVE-2019-16868CRITICAL9.8emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request w...
CVE-2019-16867MEDIUM6.5HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=del...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now