CVEs (326)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Jenkins Redhat2Job Dsl Openshift Container PlatformJun 17, 2026 Mar 8, 2019 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 A sandbox bypass vulnerability exists in Jenkins Job DSL Plugin 1.71 and earlier in job-dsl-core/src/main/groovy/javaposse/jobdsl/dsl/AbstractDslScriptLoader.groovy, job-dsl-plugin/build.gradle, job-dsl-plugin/src/main/g...Show more |
2Jenkins Redhat2Matrix Project Openshift Container PlatformJun 17, 2026 Mar 8, 2019 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java that allows attackers with Job/Configure permission to execute arbitrary c...Show more |
2Jenkins Redhat2Openshift Container Platform Pipeline\Jun 17, 2026 Mar 8, 2019 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline sc...Show more |
2Jenkins Redhat2Openshift Container Platform Script SecurityJun 17, 2026 Mar 8, 2019 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, src/main/java/org/jenkinsci/plugins/script...Show more |
2Jenkins Redhat2Openshift Container Platform Script SecurityJun 17, 2026 Feb 20, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectASTTransformsCustomizer.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endp...Show more |
5Canonical DebianF5+2 more24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+21 moreJun 17, 2026 Feb 15, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free. |
2Jenkins Redhat2Config File Provider Openshift Container PlatformJun 17, 2026 Feb 6, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configu...Show more |
2Jenkins Redhat2Blue Ocean Openshift Container PlatformJun 17, 2026 Feb 6, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Export.java, blueocean-commons/src/main/java/io/jenkin...Show more |
2Jenkins Redhat2Blue Ocean Openshift Container PlatformJun 17, 2026 Feb 6, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-core-js/src/js/bundleStartup.js, blueocean-core-js/src/js/fetch.ts, blueocean-core-js/src/js/i18n/i18n.js, blueocean-...Show more |
2Jenkins Redhat2Openshift Container Platform Token MacroJun 17, 2026 Feb 6, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An information exposure and denial of service vulnerability exists in Jenkins Token Macro Plugin 2.5 and earlier in src/main/java/org/jenkinsci/plugins/tokenmacro/Parser.java, src/main/java/org/jenkinsci/plugins/tokenmac...Show more |
2Jenkins Redhat2Git Openshift Container PlatformJun 17, 2026 Feb 6, 2019 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach correspo...Show more |
2Kube Rbac Proxy Project Redhat2Kube Rbac Proxy Openshift Container PlatformJun 17, 2026 Feb 5, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sen...Show more |
2Debian Redhat7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreJun 17, 2026 Jan 28, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to...Show more |
2Jenkins Redhat2Jenkins Openshift Container PlatformJun 17, 2026 Jan 22, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration...Show more |
2Jenkins Redhat2Jenkins Openshift Container PlatformJun 17, 2026 Jan 22, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts...Show more |
2Jenkins Redhat2Openshift Container Platform Pipeline\Jun 17, 2026 Jan 22, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy that allows atta...Show more |
2Jenkins Redhat2Openshift Container Platform Pipeline\Jun 17, 2026 Jan 22, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins/workflow/cps/CpsFlowDefinition.java, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShel...Show more |
2Jenkins Redhat2Openshift Container Platform Script SecurityJun 17, 2026 Jan 22, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide s...Show more |
2Redhat Xtermjs2Openshift Container Platform Xterm.jsJun 17, 2026 Jan 9, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js. |
4Debian FasterxmlOracle+1 more12Automation Manager Business Process Management SuiteDebian Linux+9 moreNov 21, 2024 Jan 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization. |