VYPR

Jenkins

by Jenkins Project

Source repositories

CVEs (291)

  • CVE-2021-21691CriNov 4, 2021
    risk 0.57cvss 9.8epss 0.02

    Creating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.

  • CVE-2021-21690CriNov 4, 2021
    risk 0.57cvss 9.8epss 0.03

    Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.

  • CVE-2012-4438HigNov 18, 2019
    risk 0.57cvss 8.8epss 0.02

    Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.

  • CVE-2017-1000362CriJul 17, 2017
    risk 0.57cvss 9.8epss 0.02

    The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup directory with all old secrets, and the key used to encrypt them. These backups were world-readable and not removed afterwards. Jenkins…

  • CVE-2024-23898HigJan 24, 2024
    risk 0.56cvss 8.8epss 0.67

    Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute…

  • CVE-2023-27898CriMar 10, 2023
    risk 0.56cvss 9.6epss 0.02

    Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site…

  • CVE-2015-5317HigKEVNov 25, 2015
    risk 0.56cvss 7.5epss 0.23

    The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.

  • CVE-2024-43044HigAug 7, 2024
    risk 0.53cvss 8.8epss 0.29

    Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.

  • CVE-2023-43498HigSep 20, 2023
    risk 0.53cvss 8.1epss 0.01

    In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the…

  • CVE-2023-43497HigSep 20, 2023
    risk 0.53cvss 8.1epss 0.01

    In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to…

  • CVE-2021-28165HigApr 1, 2021
    risk 0.53cvss 7.5epss 0.54

    In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.

  • CVE-2023-35141HigJun 14, 2023
    risk 0.52cvss 8.0epss 0.01

    In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by…

  • CVE-2021-21697CriNov 4, 2021
    risk 0.52cvss 9.1epss 0.02

    Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to read and write the contents of any build directory stored in Jenkins with very few restrictions.

  • CVE-2021-21689CriNov 4, 2021
    risk 0.52cvss 9.1epss 0.01

    FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access control in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.

  • CVE-2021-21685CriNov 4, 2021
    risk 0.52cvss 9.1epss 0.02

    Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create parent directories in FilePath#mkdirs.

  • CVE-2018-1999002HigJul 23, 2018
    risk 0.52cvss 7.5epss 0.86

    A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system…

  • CVE-2018-1999001HigJul 23, 2018
    risk 0.52cvss 8.8epss 0.18

    A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from the Jenkins home directory. If Jenkins…

  • CVE-2017-2608HigMay 15, 2018
    risk 0.51cvss 8.8epss 0.06

    Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserialization of various types in javax.imageio in XStream-based APIs (SECURITY-383).

  • CVE-2017-1000356HigJan 29, 2018
    risk 0.51cvss 8.8epss 0.07

    Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an issue in the Jenkins user database authentication realm: create an account if signup is enabled; or create an account if the victim is an administrator, possibly deleting the existing…

  • CVE-2026-53435HigJun 10, 2026
    risk 0.50cvss 8.8epss 0.02

    In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards.…

Page 2 of 15