2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-2154MEDIUM5.5Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configur...
CVE-2020-2153MEDIUM4.3Jenkins Backlog Plugin 2.4 and earlier transmits configured credentials in plain text as part of job configuration forms...
CVE-2020-2152MEDIUM6.1Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field...
CVE-2020-2151MEDIUM5.3Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkin...
CVE-2020-2150MEDIUM5.3Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its globa...
CVE-2020-2149MEDIUM5.3Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its glob...
CVE-2020-2148MEDIUM4.3A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to conn...
CVE-2020-2147MEDIUM4.3A cross-site request forgery vulnerability in Jenkins Mac Plugin 1.1.0 and earlier allows attackers to connect to an att...
CVE-2020-2146HIGH7.4Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabl...
CVE-2020-2145MEDIUM5.5Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenki...
CVE-2020-2144HIGH7.1Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2143MEDIUM5.3Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins c...
CVE-2020-2142MEDIUM4.3A missing permission check in Jenkins P4 Plugin 1.10.10 and earlier allows attackers with Overall/Read permission to tri...
CVE-2020-2141MEDIUM4.3A cross-site request forgery vulnerability in Jenkins P4 Plugin 1.10.10 and earlier allows attackers to trigger builds o...
CVE-2020-2140MEDIUM6.1Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation,...
CVE-2020-2139MEDIUM6.5An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the ...
CVE-2020-2138HIGH7.1Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks...
CVE-2020-2137MEDIUM4.8Jenkins Timestamper Plugin 1.11.1 and earlier does not sanitize HTML formatting of its output, resulting in a stored XSS...
CVE-2020-2136MEDIUM5.4Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field fo...
CVE-2020-2135HIGH8.8Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls...
CVE-2020-2134HIGH8.8Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor ...
CVE-2020-1737HIGH7.8A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function f...
CVE-2020-1706HIGH7It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, ...
CVE-2020-10237MEDIUM5.5An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords int...
CVE-2020-10236MEDIUM6.1An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now