Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.72% | — | Jenkins Cloudbees AWS Credentials | 18/3/2021 | 17/6/2026 | Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins in some circumstances. | |
| Modificada | Media (4.3) | 0.90% | — | Jenkins Credentials Binding | 6/5/2020 | 17/6/2026 | Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets containing a `$` character in some circumstances. | |
| Modificada | Media (6.5) | 1.1% | — | Jenkins Credentials Binding | 6/5/2020 | 17/6/2026 | Jenkins Credentials Binding Plugin 1.22 and earlier does not mask (i.e., replace with asterisks) secrets in the build log when the build contains no build steps. | |
| Modificada | Media (6.5) | 0.99% | — | Jenkins Google Oauth Credentials | 16/10/2019 | 17/6/2026 | An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able to configure jobs and credentials in Jenkins to obtain the contents of any file on the Jenkins master. | |
| Modificada | Media (6.5) | 1.5% | — | Jenkins Credentials Binding | 19/7/2019 | 17/6/2026 | Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly line #30 (passwordVariable). The attack vector is: Attacker creates and executes a Jenkins job. | |
| Modificada | Media (4.3) | 0.97% | — | Jenkins Credentials | 21/5/2019 | 17/6/2026 | Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm the existence of files on the Jenkins master with an attacker-specified path, and obtain the certificate content of files containing a PKCS#12 certificate. | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins Azure Publishersettings Credentials | 18/4/2019 | 17/6/2026 | Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml file on the Jenkins master where they could be viewed by users with access to the master file system. | |
| Modificada | Media (6.5) | 1.0% | — | Jenkins SSH Credentials | 26/6/2018 | 17/6/2026 | A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file system. | |
| Modificada | Media (4.3) | 0.66% | — | Jenkins Credentials Binding | 9/2/2018 | 17/6/2026 | Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to configured passwords being provided to… |