VYPR

Jenkins

by Jenkins Project

Source repositories

CVEs (291)

  • CVE-2016-0789MedApr 7, 2016
    risk 0.33cvss 6.1epss 0.02

    CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

  • CVE-2020-2231MedAug 12, 2020
    risk 0.32cvss 5.4epss 0.05

    Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the…

  • CVE-2020-2229MedAug 12, 2020
    risk 0.32cvss 5.4epss 0.07

    Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.

  • CVE-2020-2100MedJan 29, 2020
    risk 0.31cvss 5.8epss 0.03

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848.

  • CVE-2017-1000396MedJan 26, 2018
    risk 0.31cvss 5.9epss 0.01

    Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. This library is widely used as a transitive…

  • CVE-2017-17383MedDec 6, 2017
    risk 0.31cvss 4.7epss 0.01

    Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.

  • CVE-2020-2103MedJan 29, 2020
    risk 0.29cvss 5.4epss 0.07

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.

  • CVE-2026-84656MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to.

  • CVE-2026-84655MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.

  • CVE-2026-84646MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.

  • CVE-2026-70428MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.

  • CVE-2026-70427MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write…

  • CVE-2026-57302MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Extended Read permission or access to the Jenkins controller file system.

  • CVE-2026-53441MedJun 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site scripting (XSS) vulnerability…

  • CVE-2025-27624MedMar 5, 2025
    risk 0.28cvss 5.4epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of sidepanel widgets (e.g., Build Queue and Build Executor Status widgets).

  • CVE-2024-47804MedOct 2, 2024
    risk 0.28cvss 4.3epss 0.01

    If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates…

  • CVE-2024-47803MedOct 2, 2024
    risk 0.28cvss 4.3epss 0.01

    Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form field.

  • CVE-2023-39151MedJul 26, 2023
    risk 0.28cvss 5.4epss 0.01

    Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.

  • CVE-2023-27904MedMar 10, 2023
    risk 0.28cvss 5.3epss 0.01

    Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise inaccessible to attackers.

  • CVE-2022-41224MedSep 21, 2022
    risk 0.28cvss 5.4epss 0.01

    Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this…

Page 7 of 15