VYPR

Jenkins

by Jenkins Project

Source repositories

CVEs (276)

  • CVE-2025-31720MedApr 2, 2025
    risk 0.21cvss 4.3epss 0.00

    A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration.

  • CVE-2025-27625MedMar 5, 2025
    risk 0.21cvss 4.3epss 0.01

    In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site, because browsers…

  • CVE-2025-27623MedMar 5, 2025
    risk 0.21cvss 4.3epss 0.00

    Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via REST API or CLI, allowing attackers with View/Read permission to view encrypted values of secrets.

  • CVE-2025-27622MedMar 5, 2025
    risk 0.21cvss 4.3epss 0.01

    Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowing attackers with Agent/Extended Read permission to view encrypted values of secrets.

  • CVE-2023-43494MedSep 20, 2023
    risk 0.21cvss 4.3epss 0.03

    Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of…

  • CVE-2023-27902MedMar 10, 2023
    risk 0.21cvss 4.3epss 0.01

    Jenkins 2.393 and earlier, LTS 2.375.3 and earlier shows temporary directories related to job workspaces, which allows attackers with Item/Workspace permission to access their contents.

  • CVE-2022-20612MedJan 12, 2022
    risk 0.21cvss 4.3epss 0.02

    A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.

  • CVE-2021-21682MedOct 6, 2021
    risk 0.21cvss 4.3epss 0.01

    Jenkins 2.314 and earlier, LTS 2.303.1 and earlier accepts names of jobs and other entities with a trailing dot character, potentially replacing the configuration and data of other entities on Windows.

  • CVE-2021-21670MedJun 30, 2021
    risk 0.21cvss 4.3epss 0.02

    Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.

  • CVE-2021-21640MedApr 7, 2021
    risk 0.21cvss 4.3epss 0.02

    Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not properly check that a newly created view has an allowed name, allowing attackers with View/Create permission to create views with invalid or already-used names.

  • CVE-2021-21639MedApr 7, 2021
    risk 0.21cvss 4.3epss 0.03

    Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the `config.xml` REST API endpoint of a node, allowing attackers with Computer/Configure permission to replace a node with one of a different type.

  • CVE-2021-21606MedJan 13, 2021
    risk 0.21cvss 4.3epss 0.01

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.

  • CVE-2020-2104MedJan 29, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.

  • CVE-2019-10354MedJul 17, 2019
    risk 0.21cvss 4.3epss 0.02

    A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.

  • CVE-2018-1000862MedDec 10, 2018
    risk 0.21cvss 4.3epss 0.01

    An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build…

  • CVE-2018-1999046MedAug 23, 2018
    risk 0.21cvss 4.3epss 0.01

    A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.java that allows attackers With Overall/Read permission to access the connection log for any agent.

  • CVE-2018-1999006MedJul 23, 2018
    risk 0.21cvss 4.3epss 0.01

    A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of the most recent…

  • CVE-2018-1999004MedJul 23, 2018
    risk 0.21cvss 4.3epss 0.01

    A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches.

  • CVE-2018-1999003MedJul 23, 2018
    risk 0.21cvss 4.3epss 0.01

    A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.

  • CVE-2018-1000195MedJun 5, 2018
    risk 0.21cvss 4.3epss 0.02

    A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn whether the response is…

Page 10 of 14