VYPR

Vendor CVEs

Jenkins Project

All CVEs

1,922 total · sorted by risk
  • CVE-2017-1000505MedJan 25, 2018
    risk 0.42cvss 6.5epss 0.01

    In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coercion feature in Groovy to create new `File` objects from strings. This allowed reading arbitrary files on the Jenkins master file…

  • CVE-2017-1000104MedOct 5, 2017
    risk 0.42cvss 6.5epss 0.01

    The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs directly that allowed viewing these files. Access to view these files now…

  • CVE-2017-1000095MedOct 5, 2017
    risk 0.42cvss 6.5epss 0.01

    The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, String). These allowed circumventing many of the access restrictions implemented in the script sandbox by using e.g.…

  • CVE-2017-1000085MedOct 5, 2017
    risk 0.42cvss 6.5epss 0.01

    Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality improperly checked permissions, allowing any user with Item/Build permission (but not Item/Configure) to connect to any web…

  • CVE-2016-4986HigFeb 9, 2017
    risk 0.42cvss 7.5epss 0.03

    Directory traversal vulnerability in the TAP plugin before 1.25 in Jenkins allows remote attackers to read arbitrary files via an unspecified parameter.

  • CVE-2016-3724MedMay 17, 2016
    risk 0.42cvss 6.5epss 0.02

    Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.

  • CVE-2015-7539HigFeb 3, 2016
    risk 0.42cvss 7.5epss 0.01

    The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

  • CVE-2026-84651MedSep 2, 2026
    risk 0.41cvss 6.3epss 0.00

    In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers…

  • CVE-2022-30956MedMay 17, 2022
    risk 0.41cvss 5.4epss 0.73

    Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Rundeck webhook payloads.

  • CVE-2022-29036MedApr 12, 2022
    risk 0.41cvss 5.4epss 0.79

    Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape the name and description of Credentials parameters on views displaying parameters, resulting in a stored cross-site scripting…

  • CVE-2021-21668MedJun 16, 2021
    risk 0.41cvss 5.4epss 0.76

    Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.

  • CVE-2020-2146HigMar 9, 2020
    risk 0.41cvss 7.4epss 0.01

    Jenkins Mac Plugin 1.1.0 and earlier does not validate SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.

  • CVE-2019-1003009HigFeb 6, 2019
    risk 0.41cvss 7.4epss 0.01

    An improper certificate validation vulnerability exists in Jenkins Active Directory Plugin 2.10 and earlier in src/main/java/hudson/plugins/active_directory/ActiveDirectoryDomain.java, src/main/java/hudson/plugins/active_directory/ActiveDirectorySecurityRealm.java,…

  • CVE-2018-1999025HigAug 1, 2018
    risk 0.41cvss 7.4epss 0.01

    A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows attackers to impersonate any service that Jenkins connects to.

  • CVE-2018-1000152MedApr 5, 2018
    risk 0.41cvss 6.3epss 0.01

    An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapshot.java, Deploy.java, ExposeGuestInfo.java, FolderVSphereCloudProperty.java,…

  • CVE-2017-1000391HigJan 26, 2018
    risk 0.41cvss 7.3epss 0.01

    Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual user accounts, as well as users appearing in SCM, in directories corresponding to the user ID on disk. These directories used the user ID for their name without…

  • CVE-2017-1000091MedOct 5, 2017
    risk 0.41cvss 6.3epss 0.01

    GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan Credentials are correct). This functionality improperly checked permissions, allowing any user with Overall/Read access…

  • CVE-2016-3102HigFeb 9, 2017
    risk 0.41cvss 7.3epss 0.02

    The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array operations.

  • CVE-2016-3726HigMay 17, 2016
    risk 0.41cvss 7.4epss 0.02

    Multiple open redirect vulnerabilities in Jenkins before 2.3 and LTS before 1.651.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors related to "scheme-relative" URLs.

  • CVE-2023-41944MedSep 6, 2023
    risk 0.40cvss 6.1epss 0.01

    Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not escape the queue name parameter passed to a form validation URL, when rendering an error message, resulting in an HTML injection vulnerability.

  • CVE-2023-37947MedJul 12, 2023
    risk 0.40cvss 6.1epss 0.01

    Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.

  • CVE-2023-24445MedJan 26, 2023
    risk 0.40cvss 6.1epss 0.01

    Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins.

  • CVE-2020-2248MedSep 1, 2020
    risk 0.40cvss 6.1epss 0.01

    Jenkins JSGames Plugin 0.2 and earlier evaluates part of a URL as code, resulting in a reflected cross-site scripting (XSS) vulnerability.

  • CVE-2020-2217MedJul 2, 2020
    risk 0.40cvss 6.1epss 0.01

    Jenkins Compatibility Action Storage Plugin 1.0 and earlier does not escape the content coming from the MongoDB in the testConnection form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.

  • CVE-2020-2199MedJun 3, 2020
    risk 0.40cvss 6.1epss 0.06

    Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.

  • CVE-2020-2174MedApr 7, 2020
    risk 0.40cvss 6.1epss 0.01

    Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output, resulting in a reflected cross-site scripting vulnerability.

  • CVE-2020-2152MedMar 9, 2020
    risk 0.40cvss 6.1epss 0.01

    Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.

  • CVE-2012-4439MedNov 18, 2019
    risk 0.40cvss 6.1epss 0.02

    Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

  • CVE-2019-10376MedAug 7, 2019
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.

  • CVE-2019-10346MedJul 11, 2019
    risk 0.40cvss 6.1epss 0.02

    A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attackers inject arbitrary HTML and JavaScript into the response of this plugin.

  • CVE-2019-1003023MedFeb 6, 2019
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/java/io/jenkins/plugins/analysis/core/model/DetailsTableModel.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourceDetail.java,…

  • CVE-2019-1003003HigJan 22, 2019
    risk 0.40cvss 7.2epss 0.02

    An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never…

  • CVE-2018-1000426MedJan 9, 2019
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly…

  • CVE-2018-1000174MedMay 8, 2018
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login.

  • CVE-2018-1000144MedApr 5, 2018
    risk 0.40cvss 6.1epss 0.01

    A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in CukedoctorBaseAction#doDynamic that disables the Content-Security-Policy protection for archived artifacts and workspace files, allowing attackers able to control the…

  • CVE-2018-1000108MedMar 13, 2018
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting vulnerability exists in Jenkins CppNCSS Plugin 1.1 and earlier in AbstractProjectAction/index.jelly that allow an attacker to craft links to Jenkins URLs that run arbitrary JavaScript in the user's browser when accessed.

  • CVE-2017-1000404MedJan 26, 2018
    risk 0.40cvss 6.1epss 0.01

    The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs.

  • CVE-2017-1000389MedJan 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could have been interpreted as HTML by clients, resulting in a potential reflected…

  • CVE-2017-1000109MedOct 5, 2017
    risk 0.40cvss 6.1epss 0.01

    The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.

  • CVE-2016-4988MedFeb 9, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.

  • CVE-2023-27899HigMar 10, 2023
    risk 0.39cvss 7.0epss 0.00

    Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file…

  • CVE-2022-20619HigJan 12, 2022
    risk 0.39cvss 7.1epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials…

  • CVE-2021-43577HigNov 12, 2021
    risk 0.39cvss 7.1epss 0.01

    Jenkins OWASP Dependency-Check Plugin 5.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2021-21680HigAug 31, 2021
    risk 0.39cvss 7.1epss 0.01

    Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) attacks.

  • CVE-2021-21656HigMay 11, 2021
    risk 0.39cvss 7.1epss 0.02

    Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2021-21655HigMay 11, 2021
    risk 0.39cvss 7.1epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified Perforce server using attacker-specified username and password.

  • CVE-2020-2144HigMar 9, 2020
    risk 0.39cvss 7.1epss 0.01

    Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2140MedMar 9, 2020
    risk 0.39cvss 6.1epss 0.76

    Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.

  • CVE-2020-2138HigMar 9, 2020
    risk 0.39cvss 7.1epss 0.01

    Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2019-1003044HigMar 28, 2019
    risk 0.39cvss 7.1epss 0.01

    A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Page 16 of 39