VYPR

Vendor CVEs

Jenkins Project

All CVEs

1,922 total · sorted by risk
  • CVE-2019-10428HigSep 25, 2019
    risk 0.49cvss 7.5epss 0.01

    Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2019-10381HigAug 7, 2019
    risk 0.49cvss 7.5epss 0.01

    Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

  • CVE-2018-1999043HigAug 23, 2018
    risk 0.49cvss 7.5epss 0.02

    A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows attackers to create ephemeral in-memory user records by attempting to log in using invalid credentials.

  • CVE-2017-1000108HigOct 5, 2017
    risk 0.49cvss 7.5epss 0.01

    The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission instead.

  • CVE-2017-1000092HigOct 5, 2017
    risk 0.49cvss 7.5epss 0.01

    Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at a username/password credentials ID could trick a developer with job configuration permissions into following a link with a…

  • CVE-2026-84675HigSep 2, 2026
    risk 0.48cvss 7.4epss 0.01

    OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable values to execute arbitrary commands on the agent running the build.

  • CVE-2022-30945HigMay 17, 2022
    risk 0.48cvss 8.5epss 0.01

    Jenkins Pipeline: Groovy Plugin 2689.v434009a_31b_f1 and earlier allows loading any Groovy source files on the classpath of Jenkins and Jenkins plugins in sandboxed pipelines.

  • CVE-2018-1999035HigAug 1, 2018
    risk 0.48cvss 7.4epss 0.01

    A man in the middle vulnerability exists in Jenkins Inedo BuildMaster Plugin 1.3 and earlier in BuildMasterConfiguration.java, BuildMasterConfig.java, BuildMasterApi.java that allows attackers to impersonate any service that Jenkins connects to.

  • CVE-2018-1999034HigAug 1, 2018
    risk 0.48cvss 7.4epss 0.01

    A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.java that allows attackers to impersonate any service that Jenkins connects to.

  • CVE-2018-1000605HigJun 26, 2018
    risk 0.48cvss 7.4epss 0.01

    A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidator.java that allows attackers to impersonate any service that Jenkins connects to.

  • CVE-2018-8718HigMar 27, 2018
    risk 0.48cvss 8.0epss 0.05

    Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.

  • CVE-2026-84652HigSep 2, 2026
    risk 0.47cvss 7.3epss 0.00

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which…

  • CVE-2019-10475MedOct 23, 2019
    risk 0.47cvss 6.1epss 0.58

    A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.

  • CVE-2019-1003004HigJan 22, 2019
    risk 0.47cvss 7.2epss 0.02

    An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration of active HTTP sessions indefinitely even though the user…

  • CVE-2018-1000863HigDec 10, 2018
    risk 0.47cvss 8.2epss 0.04

    A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim…

  • CVE-2018-1000608HigJun 26, 2018
    risk 0.47cvss 7.2epss 0.01

    A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker with local file system access or control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the…

  • CVE-2018-1000056HigFeb 9, 2018
    risk 0.47cvss 8.3epss 0.01

    Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service…

  • CVE-2026-84667HigSep 2, 2026
    risk 0.46cvss 7.1epss 0.00

    Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapler data binding, allowing attackers to redirect backup writes to an attacker-specified directory and to include arbitrary files from the Jenkins controller file system…

  • CVE-2026-70448HigAug 5, 2026
    risk 0.46cvss 7.1epss 0.00

    Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.

  • CVE-2026-57303HigJun 24, 2026
    risk 0.46cvss 7.1epss 0.00

    Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side…

  • CVE-2025-64134HigOct 29, 2025
    risk 0.46cvss 7.1epss 0.00

    Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-46654HigOct 25, 2023
    risk 0.46cvss 8.1epss 0.01

    Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to delete arbitrary files on the…

  • CVE-2023-37965HigJul 12, 2023
    risk 0.46cvss 7.1epss 0.01

    A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2023-37949HigJul 12, 2023
    risk 0.46cvss 7.1epss 0.01

    A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in…

  • CVE-2023-28685HigMar 22, 2023
    risk 0.46cvss 7.1epss 0.01

    Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-45381HigNov 15, 2022
    risk 0.46cvss 8.1epss 0.01

    Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of Apache Commons Configuration library that enable the 'file:' prefix interpolator by default, allowing attackers able to configure Pipelines…

  • CVE-2022-36900HigJul 27, 2022
    risk 0.46cvss 8.2epss 0.01

    Jenkins Compuware zAdviser API Plugin 1.0.3 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.

  • CVE-2022-36881HigJul 27, 2022
    risk 0.46cvss 8.1epss 0.01

    Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.

  • CVE-2022-28140HigMar 29, 2022
    risk 0.46cvss 8.1epss 0.01

    Jenkins Flaky Test Handler Plugin 1.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2021-21686HigNov 4, 2021
    risk 0.46cvss 8.1epss 0.02

    File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories.

  • CVE-2020-2321HigDec 3, 2020
    risk 0.46cvss 8.1epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to shelve, unshelve, or delete a project.

  • CVE-2020-2284HigSep 23, 2020
    risk 0.46cvss 7.1epss 0.01

    Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2245HigSep 1, 2020
    risk 0.46cvss 7.1epss 0.01

    Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2178HigApr 16, 2020
    risk 0.46cvss 7.1epss 0.01

    Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2091HigJan 15, 2020
    risk 0.46cvss 8.1epss 0.01

    A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained through another method.

  • CVE-2019-16561HigDec 17, 2019
    risk 0.46cvss 7.1epss 0.01

    Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate and hostname validation for the entire Jenkins master JVM.

  • CVE-2019-16549HigDec 17, 2019
    risk 0.46cvss 8.1epss 0.01

    Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-middle attackers to have Jenkins parse crafted XML documents.

  • CVE-2019-10462HigOct 23, 2019
    risk 0.46cvss 8.1epss 0.01

    A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed attackers to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2019-10446HigOct 16, 2019
    risk 0.46cvss 8.2epss 0.01

    Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.

  • CVE-2019-10327HigMay 31, 2019
    risk 0.46cvss 8.1epss 0.01

    An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a temporary directory's content on the agent running the Maven build to have Jenkins parse a maliciously crafted XML file that uses…

  • CVE-2019-1003049HigApr 10, 2019
    risk 0.46cvss 8.1epss 0.02

    Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject…

  • CVE-2019-1003011HigFeb 6, 2019
    risk 0.46cvss 8.1epss 0.02

    An information exposure and denial of service vulnerability exists in Jenkins Token Macro Plugin 2.5 and earlier in src/main/java/org/jenkinsci/plugins/tokenmacro/Parser.java, src/main/java/org/jenkinsci/plugins/tokenmacro/TokenMacro.java, src/main/java/org/jenkinsci/plugins/toke…

  • CVE-2018-1000417HigJan 9, 2019
    risk 0.46cvss 8.1epss 0.01

    A cross-site request forgery vulnerability exists in Jenkins Email Extension Template Plugin 1.0 and earlier in ExtEmailTemplateManagement.java that allows creating or removing templates.

  • CVE-2018-1000414HigJan 9, 2019
    risk 0.46cvss 8.1epss 0.01

    A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigFileAction.java that allows creating and editing configuration file definitions.

  • CVE-2018-1000194HigJun 5, 2018
    risk 0.46cvss 8.1epss 0.03

    A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.

  • CVE-2017-1000504HigJan 24, 2018
    risk 0.46cvss 8.1epss 0.01

    A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initialization. There is a very short window of time after startup during which Jenkins may no longer show the 'Please wait while Jenkins…

  • CVE-2017-1000503HigJan 24, 2018
    risk 0.46cvss 8.1epss 0.01

    A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of execution of commands during initialization. This could in rare cases result in failure to initialize the setup wizard on the first startup. This resulted in multiple…

  • CVE-2026-27099HigFeb 18, 2026
    risk 0.45cvss 8.0epss 0.00

    Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with…

  • CVE-2025-5806HigJun 6, 2025
    risk 0.45cvss 8.0epss 0.01

    Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.

  • CVE-2022-41232HigSep 21, 2022
    risk 0.45cvss 8.0epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers to replace any config.xml file on the Jenkins controller file system with an empty file by providing a crafted file name to an API endpoint.

Page 10 of 39