2020 CVE Vulnerabilities

21,074 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-7733HIGH7.5The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for ...
CVE-2020-2278MEDIUM6.5Jenkins Storable Configs Plugin 1.0 and earlier does not restrict the user-specified file name, allowing attackers with ...
CVE-2020-2277MEDIUM6.5Jenkins Storable Configs Plugin 1.0 and earlier allows users with Job/Read permission to read arbitrary files on the Jen...
CVE-2020-2276HIGH8.8Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing att...
CVE-2020-2275MEDIUM6.5Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins co...
CVE-2020-2274MEDIUM5.5Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the...
CVE-2020-2273MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers to conne...
CVE-2020-2272MEDIUM4.3A missing permission check in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers with Overall/Read permission to...
CVE-2020-2271MEDIUM5.4Jenkins Locked Files Report Plugin 1.6 and earlier does not escape locked files' names in tooltips, resulting in a store...
CVE-2020-2270MEDIUM5.4Jenkins ClearCase Release Plugin 0.3 and earlier does not escape the composite baseline in badge tooltip, resulting in a...
CVE-2020-2269MEDIUM5.4Jenkins chosen-views-tabbar Plugin 1.2 and earlier does not escape view names in the dropdown to select views, resulting...
CVE-2020-2268HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain acc...
CVE-2020-2267MEDIUM4.3A missing permission check in Jenkins MongoDB Plugin 1.3 and earlier allows attackers with Overall/Read permission to ga...
CVE-2020-2266MEDIUM5.4Jenkins Description Column Plugin 1.3 and earlier does not escape the job description in the column tooltip, resulting i...
CVE-2020-2265MEDIUM5.4Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not escape the method information in tooltips, re...
CVE-2020-2264MEDIUM5.4Jenkins Custom Job Icon Plugin 0.2 and earlier does not escape the job descriptions in tooltips, resulting in a stored c...
CVE-2020-2263MEDIUM5.4Jenkins Radiator View Plugin 1.29 and earlier does not escape the full name of the jobs in tooltips, resulting in a stor...
CVE-2020-2262MEDIUM5.4Jenkins Android Lint Plugin 2.6 and earlier does not escape the annotation message in tooltips, resulting in a stored cr...
CVE-2020-2261HIGH8.8Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Confi...
CVE-2020-2260MEDIUM4.3A missing permission check in Jenkins Perfecto Plugin 1.17 and earlier allows attackers with Overall/Read permission to ...
CVE-2020-2259MEDIUM5.4Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored c...
CVE-2020-2258MEDIUM4.3Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP en...
CVE-2020-2257MEDIUM5.4Jenkins Validating String Parameter Plugin 2.4 and earlier does not escape various user-controlled fields, resulting in ...
CVE-2020-2256MEDIUM5.4Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as par...
CVE-2020-2255MEDIUM4.3A missing permission check in Jenkins Blue Ocean Plugin 1.23.2 and earlier allows attackers with Overall/Read permission...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now