VYPR

Bitnami package

jenkins

pkg:bitnami/jenkins

Vulnerabilities (128)

  • CVE-2026-84657MedSep 2, 2026
    affected < 2.568.3fixed 2.568.3

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users.

  • CVE-2026-84656MedSep 2, 2026
    affected < 2.568.3fixed 2.568.3

    A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to.

  • CVE-2026-84655MedSep 2, 2026
    affected < 2.568.3fixed 2.568.3

    Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.

  • CVE-2026-84654MedSep 2, 2026
    affected < 2.568.3fixed 2.568.3

    In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuration object, allowing attackers who can submit configuration fo

  • CVE-2026-84653LowSep 2, 2026
    affected >= 2.421.0, < 2.568.3fixed 2.568.3

    Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should n

  • CVE-2026-84652HigSep 2, 2026
    affected < 2.568.3fixed 2.568.3

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which

  • CVE-2026-84651MedSep 2, 2026
    affected < 2.568.3fixed 2.568.3

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers wit

  • CVE-2026-84650HigSep 2, 2026
    affected < 2.568.3fixed 2.568.3

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields a

  • CVE-2026-84649HigSep 2, 2026
    affected >= 2.447.0, < 2.568.3fixed 2.568.3

    In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resour

  • CVE-2026-84648HigSep 2, 2026
    affected < 2.568.3fixed 2.568.3

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.

  • CVE-2026-84647HigSep 2, 2026
    affected < 2.568.3fixed 2.568.3

    In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field t

  • CVE-2026-84646MedSep 2, 2026
    affected < 2.568.3fixed 2.568.3

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.

  • CVE-2026-84645HigSep 2, 2026
    affected < 2.568.3fixed 2.568.3

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` docum

  • CVE-2026-70430LowAug 5, 2026
    affected < 2.568.2fixed 2.568.2

    Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, incl

  • CVE-2026-70429MedAug 5, 2026
    affected < 2.568.2fixed 2.568.2

    Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted the

  • CVE-2026-70428MedAug 5, 2026
    affected < 2.568.2fixed 2.568.2

    Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.

  • CVE-2026-70427MedAug 5, 2026
    affected < 2.568.2fixed 2.568.2

    Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write

  • CVE-2026-70426CriAug 5, 2026
    affected < 2.568.2fixed 2.568.2

    In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing age

  • CVE-2026-53442MedJun 10, 2026
    affected < 2.555.3fixed 2.555.3

    Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permissio

  • CVE-2026-53441MedJun 10, 2026
    affected >= 2.483.0, < 2.555.3fixed 2.555.3

    Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site scripting (XSS) vulnerability

Page 1 of 7