VYPR
Vendor

Jenkins Project

Products
1,351
CVEs
1,869
Across products
739
Status
Private

Products

1,351
View all 1,351 products →

Recent CVEs

1,869
View all 1,869 CVEs →
  • CVE-2024-23897CriKEVJan 24, 2024
    risk 0.86cvss 9.8epss 1.00

    Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins…

  • CVE-2018-1000861CriKEVDec 10, 2018
    risk 0.80cvss 9.8epss 0.98

    A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs…

  • CVE-2017-1000353CriKEVJan 29, 2018
    risk 0.80cvss 9.8epss 1.00

    Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that…

  • CVE-2016-9299CriJan 12, 2017
    risk 0.67cvss 9.8epss 0.97

    The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.

  • CVE-2015-8103CriNov 25, 2015
    risk 0.67cvss 9.8epss 0.87

    The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a problematic webapps/ROOT/WEB-INF/lib/commons-collections-*.jar file and the "Groovy variant in…

  • CVE-2023-44487HigKEVOct 10, 2023
    risk 0.65cvss 7.5epss 1.00

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2019-10458CriOct 16, 2019
    risk 0.65cvss 9.9epss 0.02

    Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, allowing attackers able to execute Script Security protected scripts to execute arbitrary code.

  • CVE-2019-1003032CriMar 8, 2019
    risk 0.65cvss 9.9epss 0.02

    A sandbox bypass vulnerability exists in Jenkins Email Extension Plugin 2.64 and earlier in pom.xml, src/main/java/hudson/plugins/emailext/ExtendedEmailPublisher.java, src/main/java/hudson/plugins/emailext/plugins/content/EmailExtScript.java,…

  • CVE-2025-47889CriMay 14, 2025
    risk 0.64cvss 9.8epss 0.01

    In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames…

  • CVE-2023-49656CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-49654CriNov 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system.

  • CVE-2023-28677CriApr 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Jenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build Environment, Build Steps, and Post-build Actions to the equivalent Pipeline step invocations, allowing attackers able to configure Freestyle projects to…

  • CVE-2023-24444CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login.

  • CVE-2022-45400CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-45396CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-45395CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-43406CriOct 19, 2022
    risk 0.64cvss 9.9epss 0.01

    A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox…

  • CVE-2022-43405CriOct 19, 2022
    risk 0.64cvss 9.9epss 0.01

    A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and…

  • CVE-2022-43404CriOct 19, 2022
    risk 0.64cvss 9.9epss 0.01

    A sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic constructors in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including…

  • CVE-2022-43403CriOct 19, 2022
    risk 0.64cvss 9.9epss 0.01

    A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection…