VYPR

Jenkins

by Jenkins Project

Source repositories

CVEs (291)

  • CVE-2018-1999047MedAug 23, 2018
    risk 0.42cvss 6.5epss 0.01

    A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.

  • CVE-2017-1000394HigJan 26, 2018
    risk 0.42cvss 7.5epss 0.01

    Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.

  • CVE-2016-3724MedMay 17, 2016
    risk 0.42cvss 6.5epss 0.02

    Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.

  • CVE-2015-7539HigFeb 3, 2016
    risk 0.42cvss 7.5epss 0.01

    The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

  • CVE-2026-84651MedSep 2, 2026
    risk 0.41cvss 6.3epss 0.00

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers…

  • CVE-2017-1000391HigJan 26, 2018
    risk 0.41cvss 7.3epss 0.01

    Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual user accounts, as well as users appearing in SCM, in directories corresponding to the user ID on disk. These directories used the user ID for their name without…

  • CVE-2016-3726HigMay 17, 2016
    risk 0.41cvss 7.4epss 0.02

    Multiple open redirect vulnerabilities in Jenkins before 2.3 and LTS before 1.651.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors related to "scheme-relative" URLs.

  • CVE-2012-4439MedNov 18, 2019
    risk 0.40cvss 6.1epss 0.02

    Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

  • CVE-2019-1003003HigJan 22, 2019
    risk 0.40cvss 7.2epss 0.02

    An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never…

  • CVE-2023-27899HigMar 10, 2023
    risk 0.39cvss 7.0epss 0.00

    Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file…

  • CVE-2020-2230MedAug 12, 2020
    risk 0.38cvss 5.4epss 0.83

    Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.

  • CVE-2019-10352MedJul 17, 2019
    risk 0.36cvss 6.5epss 0.04

    A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting…

  • CVE-2018-6356MedFeb 20, 2018
    risk 0.36cvss 6.5epss 0.04

    Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not…

  • CVE-2026-84677MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin…

  • CVE-2026-84654MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuration object, allowing attackers who can submit configuration…

  • CVE-2025-59474MedSep 17, 2025
    risk 0.35cvss 5.3epss 0.05

    Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel…

  • CVE-2023-43495MedSep 20, 2023
    risk 0.35cvss 5.4epss 0.01

    Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of 'ExpandableDetailsNote', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control this parameter.

  • CVE-2022-34173MedJun 23, 2022
    risk 0.35cvss 5.4epss 0.01

    In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2022-34172MedJun 23, 2022
    risk 0.35cvss 5.4epss 0.01

    In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.

  • CVE-2022-34171MedJun 23, 2022
    risk 0.35cvss 5.4epss 0.01

    In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335)…

Page 5 of 15