VYPR

Jenkins

by Jenkins Project

Source repositories

CVEs (291)

  • CVE-2022-34172MedJun 23, 2022
    risk 0.35cvss 5.4epss 0.01

    In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.

  • CVE-2022-34171MedJun 23, 2022
    risk 0.35cvss 5.4epss 0.01

    In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335)…

  • CVE-2021-21683MedOct 6, 2021
    risk 0.35cvss 6.5epss 0.02

    The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Overall/Read permission (Windows controller) or Job/Workspace permission (Windows…

  • CVE-2021-21615MedJan 26, 2021
    risk 0.35cvss 5.3epss 0.01

    Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.

  • CVE-2021-21607MedJan 13, 2021
    risk 0.35cvss 6.5epss 0.01

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to request crafted URLs that use all available memory in Jenkins, potentially leading to out of memory errors.

  • CVE-2021-21602MedJan 13, 2021
    risk 0.35cvss 6.5epss 0.02

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.

  • CVE-2020-2163MedMar 25, 2020
    risk 0.35cvss 5.4epss 0.01

    Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerability exploitable by users able to control column headers.

  • CVE-2020-2161MedMar 25, 2020
    risk 0.35cvss 5.4epss 0.01

    Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.

  • CVE-2019-10403MedSep 25, 2019
    risk 0.35cvss 5.4epss 0.01

    Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions.

  • CVE-2018-1000408MedJan 9, 2019
    risk 0.35cvss 6.5epss 0.01

    A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in…

  • CVE-2018-1000864MedDec 10, 2018
    risk 0.35cvss 6.5epss 0.03

    A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.

  • CVE-2018-1999044MedAug 23, 2018
    risk 0.35cvss 6.5epss 0.01

    A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.

  • CVE-2017-1000355MedJan 29, 2018
    risk 0.35cvss 6.5epss 0.02

    Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void.

  • CVE-2016-0790MedApr 7, 2016
    risk 0.35cvss 5.3epss 0.02

    Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.

  • CVE-2024-43045MedAug 7, 2024
    risk 0.34cvss 6.3epss 0.04

    Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to access other users' "My Views".

  • CVE-2021-21610MedJan 13, 2021
    risk 0.33cvss 6.1epss 0.01

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted preview of markup passed as a query parameter, resulting in a reflected cross-site scripting (XSS) vulnerability if the configured markup formatter does not…

  • CVE-2012-4441MedNov 18, 2019
    risk 0.33cvss 6.1epss 0.02

    Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.

  • CVE-2012-4440MedNov 18, 2019
    risk 0.33cvss 6.1epss 0.02

    Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.

  • CVE-2019-10405MedSep 25, 2019
    risk 0.33cvss 5.4epss 0.65

    Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers exploiting another XSS vulnerability to obtain the HTTP session cookie despite it being marked HttpOnly.

  • CVE-2018-1000407MedJan 9, 2019
    risk 0.33cvss 6.1epss 0.02

    A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by Jenkins.

Page 6 of 15