VYPR

Jenkins

by Jenkins Project

Source repositories

CVEs (276)

  • CVE-2019-10402MedSep 25, 2019
    risk 0.28cvss 5.4epss 0.01

    In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:combobox form control interpreted its item labels as HTML, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents.

  • CVE-2019-10401MedSep 25, 2019
    risk 0.28cvss 5.4epss 0.01

    In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as HTML when expanded, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents (typically Job/Configure).

  • CVE-2019-1003050MedApr 10, 2019
    risk 0.28cvss 5.4epss 0.01

    The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.

  • CVE-2018-1000409MedJan 9, 2019
    risk 0.28cvss 5.4epss 0.01

    A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing session and creating a new one when a user signed up for a…

  • CVE-2018-1999045MedAug 23, 2018
    risk 0.28cvss 5.4epss 0.01

    A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2.java that allows attackers with a valid cookie to remain logged in even if that feature is disabled.

  • CVE-2018-1999042MedAug 23, 2018
    risk 0.28cvss 5.3epss 0.01

    A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.

  • CVE-2018-1999007MedJul 23, 2018
    risk 0.28cvss 5.4epss 0.01

    A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would…

  • CVE-2018-1999005MedJul 23, 2018
    risk 0.28cvss 5.4epss 0.01

    A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser…

  • CVE-2017-2613MedMay 15, 2018
    risk 0.28cvss 5.4epss 0.02

    jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record was only retained until restart in most cases, administrators' web browsers could be manipulated to create a large number of user records (SECURITY-406).

  • CVE-2017-2610MedMay 15, 2018
    risk 0.28cvss 5.4epss 0.02

    jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in search suggestions due to improperly escaping users with less-than and greater-than characters in their names (SECURITY-388).

  • CVE-2017-2612MedMay 15, 2018
    risk 0.28cvss 5.4epss 0.02

    In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds possibly failing to download a JDK.

  • CVE-2017-2601MedMay 10, 2018
    risk 0.28cvss 5.4epss 0.02

    Jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in parameter names and descriptions (SECURITY-353). Users with the permission to configure jobs were able to inject JavaScript into parameter names and descriptions.

  • CVE-2018-1000170MedApr 16, 2018
    risk 0.28cvss 5.4epss 0.01

    A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name containing JavaScript that would be executed…

  • CVE-2018-1000169MedApr 16, 2018
    risk 0.28cvss 5.3epss 0.01

    An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler.java that allows unauthorized attackers to confirm the existence of agents or views with an attacker-specified name by sending a…

  • CVE-2017-2599MedApr 11, 2018
    risk 0.28cvss 5.4epss 0.01

    Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).

  • CVE-2018-1000068MedFeb 16, 2018
    risk 0.28cvss 5.3epss 0.02

    An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on…

  • CVE-2018-1000067MedFeb 16, 2018
    risk 0.28cvss 5.3epss 0.02

    An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.

  • CVE-2014-9635MedSep 12, 2017
    risk 0.28cvss 5.3epss 0.03

    Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

  • CVE-2014-9634MedSep 12, 2017
    risk 0.28cvss 5.3epss 0.03

    Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.

  • CVE-2016-3725MedMay 17, 2016
    risk 0.28cvss 4.3epss 0.02

    Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of update site metadata by leveraging a missing permissions check. NOTE: this issue can be combined with DNS cache poisoning to cause a denial of service (service disruption).

Page 8 of 14