VYPR

Jenkins

by Jenkins Project

Source repositories

CVEs (276)

  • CVE-2018-1000193MedJun 5, 2018
    risk 0.21cvss 4.3epss 0.01

    A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as…

  • CVE-2018-1000192MedJun 5, 2018
    risk 0.21cvss 4.3epss 0.01

    A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.

  • CVE-2017-2598MedMay 23, 2018
    risk 0.21cvss 4.3epss 0.01

    Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).

  • CVE-2017-2609MedMay 22, 2018
    risk 0.21cvss 4.3epss 0.02

    jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autocomplete feature on the search box discloses the names of the views in its suggestions, including the ones for which the current user does…

  • CVE-2017-2604MedMay 15, 2018
    risk 0.21cvss 4.3epss 0.01

    In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not being consistently protected by permission checks (SECURITY-371).

  • CVE-2017-2600MedMay 15, 2018
    risk 0.21cvss 4.3epss 0.01

    In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of these nodes (SECURITY-343).

  • CVE-2017-2606MedMay 8, 2018
    risk 0.21cvss 4.3epss 0.02

    Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that should not be visible (SECURITY-380). This only affects anonymous users (other users legitimately have access) that were able to get a list of…

  • CVE-2017-2611MedMay 8, 2018
    risk 0.21cvss 4.3epss 0.02

    Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins to trigger these…

  • CVE-2017-1000400MedJan 26, 2018
    risk 0.21cvss 4.3epss 0.01

    The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This…

  • CVE-2017-1000399MedJan 26, 2018
    risk 0.21cvss 4.3epss 0.01

    The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in the queue (typically builds waiting to start). This included information about tasks that the current user otherwise has no access to, e.g. due to lack of…

  • CVE-2017-1000398MedJan 26, 2018
    risk 0.21cvss 4.3epss 0.01

    The remote API in Jenkins 2.73.1 and earlier, 2.83 and earlier at /computer/(agent-name)/api showed information about tasks (typically builds) currently running on that agent. This included information about tasks that the current user otherwise has no access to, e.g. due to…

  • CVE-2017-1000395MedJan 26, 2018
    risk 0.21cvss 4.3epss 0.01

    Jenkins 2.73.1 and earlier, 2.83 and earlier provides information about Jenkins user accounts which is generally available to anyone with Overall/Read permissions via the /user/(username)/api remote API. This included e.g. Jenkins users' email addresses if the Mailer Plugin is…

  • CVE-2016-3727MedMay 17, 2016
    risk 0.21cvss 4.3epss 0.02

    The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.

  • CVE-2026-70430LowAug 5, 2026
    risk 0.18cvss 2.7epss 0.00

    Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration,…

  • CVE-2025-67639LowDec 10, 2025
    risk 0.16cvss 3.5epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account.

  • CVE-2017-2602LowMay 15, 2018
    risk 0.13cvss 3.1epss 0.02

    jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the agent-to-master security subsystem. This could allow metadata files to be written to by malicious agents (SECURITY-358).

  • CVE-2017-2603LowMay 15, 2018
    risk 0.10cvss 2.6epss 0.01

    Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).

  • CVE-2017-1000401LowJan 26, 2018
    risk 0.07cvss 2.2epss 0.00

    The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, <f:password/>, supports form validation (e.g. for API keys). The form validation AJAX requests were sent via GET, which could result in secrets being logged to a HTTP access…

  • CVE-2013-5573Dec 31, 2013
    risk 0.03cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web script or HTML via the Description field in the user configuration.

  • CVE-2026-19429Aug 10, 2026
    risk 0.00cvss epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Page 11 of 14