2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-2154 | MEDIUM | 5.5 | 0.3% | Mar 9, 2020 | Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configur... |
| CVE-2020-2153 | MEDIUM | 4.3 | 0.6% | Mar 9, 2020 | Jenkins Backlog Plugin 2.4 and earlier transmits configured credentials in plain text as part of job configuration forms... |
| CVE-2020-2152 | MEDIUM | 6.1 | 1.2% | Mar 9, 2020 | Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field... |
| CVE-2020-2151 | MEDIUM | 5.3 | 0.7% | Mar 9, 2020 | Jenkins Quality Gates Plugin 2.5 and earlier transmits configured credentials in plain text as part of its global Jenkin... |
| CVE-2020-2150 | MEDIUM | 5.3 | 0.6% | Mar 9, 2020 | Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its globa... |
| CVE-2020-2149 | MEDIUM | 5.3 | 0.6% | Mar 9, 2020 | Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its glob... |
| CVE-2020-2148 | MEDIUM | 4.3 | 0.8% | Mar 9, 2020 | A missing permission check in Jenkins Mac Plugin 1.1.0 and earlier allows attackers with Overall/Read permission to conn... |
| CVE-2020-2147 | MEDIUM | 4.3 | 0.8% | Mar 9, 2020 | A cross-site request forgery vulnerability in Jenkins Mac Plugin 1.1.0 and earlier allows attackers to connect to an att... |
| CVE-2020-2146 | HIGH | 7.4 | 0.6% | Mar 9, 2020 | Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabl... |
| CVE-2020-2145 | MEDIUM | 5.5 | 0.3% | Mar 9, 2020 | Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenki... |
| CVE-2020-2144 | HIGH | 7.1 | 1.1% | Mar 9, 2020 | Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2020-2143 | MEDIUM | 5.3 | 0.6% | Mar 9, 2020 | Jenkins Logstash Plugin 2.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins c... |
| CVE-2020-2142 | MEDIUM | 4.3 | 0.6% | Mar 9, 2020 | A missing permission check in Jenkins P4 Plugin 1.10.10 and earlier allows attackers with Overall/Read permission to tri... |
| CVE-2020-2141 | MEDIUM | 4.3 | 0.6% | Mar 9, 2020 | A cross-site request forgery vulnerability in Jenkins P4 Plugin 1.10.10 and earlier allows attackers to trigger builds o... |
| CVE-2020-2140 | MEDIUM | 6.1 | 76.0% | Mar 9, 2020 | Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation,... |
| CVE-2020-2139 | MEDIUM | 6.5 | 1.6% | Mar 9, 2020 | An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the ... |
| CVE-2020-2138 | HIGH | 7.1 | 0.9% | Mar 9, 2020 | Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks... |
| CVE-2020-2137 | MEDIUM | 4.8 | 0.7% | Mar 9, 2020 | Jenkins Timestamper Plugin 1.11.1 and earlier does not sanitize HTML formatting of its output, resulting in a stored XSS... |
| CVE-2020-2136 | MEDIUM | 5.4 | 0.9% | Mar 9, 2020 | Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field fo... |
| CVE-2020-2135 | HIGH | 8.8 | 1.0% | Mar 9, 2020 | Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls... |
| CVE-2020-2134 | HIGH | 8.8 | 1.0% | Mar 9, 2020 | Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor ... |
| CVE-2020-1737 | HIGH | 7.8 | 0.4% | Mar 9, 2020 | A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function f... |
| CVE-2020-1706 | HIGH | 7 | 0.2% | Mar 9, 2020 | It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, ... |
| CVE-2020-10237 | MEDIUM | 5.5 | 0.2% | Mar 9, 2020 | An issue was discovered in Froxlor through 0.10.15. The installer wrote configuration parameters including passwords int... |
| CVE-2020-10236 | MEDIUM | 6.1 | 0.3% | Mar 9, 2020 | An issue was discovered in Froxlor before 0.10.14. It created files with static names in /tmp during installation if the... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now