CloudBees records
10 published records for vendor cloudbees.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 90%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-20 Improper Input Validation2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-522 Insufficiently Protected Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-11350No exploit | CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via thecloudbees · jenkins operations center · CWE-522 | Critical9.8 | — | 1.8% | Apr 19, 2019 |
31Monitor | CVE-2012-0785No exploit | Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before cloudbees · jenkins · CWE-400 | High7.5 | — | 3.4% | Feb 24, 2020 |
27Monitor | CVE-2013-2034No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.cloudbees · jenkins · CWE-352 | Medium6.8 | — | 1.6% | May 14, 2014 |
24Monitor | CVE-2012-6073No exploit | Open redirect vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x bjenkins · jenkins · CWE-20 | Medium5.8 | — | 1.8% | Feb 24, 2013 |
18Monitor | CVE-2012-6072No exploit | CRLF injection vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x jenkins · jenkins · CWE-20 | Medium4.3 | — | 1.8% | Feb 24, 2013 |
17Monitor | CVE-2012-0324No exploit | Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.jenkins · jenkins · CWE-79 | Medium4.3 | — | 1.1% | Mar 9, 2012 |
17Monitor | CVE-2012-0325No exploit | Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.jenkins · jenkins · CWE-79 | Medium4.3 | — | 1.1% | Mar 9, 2012 |
14Monitor | CVE-2012-6074No exploit | Cross-site scripting (XSS) vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.jenkins · jenkins · CWE-79 | Low3.5 | — | 1.4% | Feb 24, 2013 |
11Monitor | CVE-2013-0158No exploit | Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x bjenkins · jenkins | Low2.6 | — | 2.5% | Feb 24, 2013 |
9Monitor | CVE-2013-2033No exploit | Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x bjenkins · jenkins · CWE-79 | Low2.1 | — | 1.9% | Apr 10, 2014 |
- CVE-2019-1135040Plan
CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the
CriticalCVSS 9.8No exploitEPSS 2%cloudbees · jenkins operations centerApr 19, 2019
- CVE-2012-078531Monitor
Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before
HighCVSS 7.5No exploitEPSS 3%cloudbees · jenkinsFeb 24, 2020
- CVE-2013-203427Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.
MediumCVSS 6.8No exploitEPSS 2%cloudbees · jenkinsMay 14, 2014
- CVE-2012-607324Monitor
Open redirect vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x b
MediumCVSS 5.8No exploitEPSS 2%jenkins · jenkinsFeb 24, 2013
- CVE-2012-607218Monitor
CRLF injection vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x
MediumCVSS 4.3No exploitEPSS 2%jenkins · jenkinsFeb 24, 2013
- CVE-2012-032417Monitor
Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.
MediumCVSS 4.3No exploitEPSS 1%jenkins · jenkinsMar 9, 2012
- CVE-2012-032517Monitor
Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.
MediumCVSS 4.3No exploitEPSS 1%jenkins · jenkinsMar 9, 2012
- CVE-2012-607414Monitor
Cross-site scripting (XSS) vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.
LowCVSS 3.5No exploitEPSS 1%jenkins · jenkinsFeb 24, 2013
- CVE-2013-015811Monitor
Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x b
LowCVSS 2.6No exploitEPSS 2%jenkins · jenkinsFeb 24, 2013
- CVE-2013-20339Monitor
Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x b
LowCVSS 2.1No exploitEPSS 2%jenkins · jenkinsApr 10, 2014