VYPR

Vendor CVEs

Jenkins Project

All CVEs

1,869 total · sorted by risk
  • CVE-2018-1000426MedJan 9, 2019
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly…

  • CVE-2018-1000174MedMay 8, 2018
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login.

  • CVE-2018-1000144MedApr 5, 2018
    risk 0.40cvss 6.1epss 0.01

    A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in CukedoctorBaseAction#doDynamic that disables the Content-Security-Policy protection for archived artifacts and workspace files, allowing attackers able to control the…

  • CVE-2018-1000108MedMar 13, 2018
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting vulnerability exists in Jenkins CppNCSS Plugin 1.1 and earlier in AbstractProjectAction/index.jelly that allow an attacker to craft links to Jenkins URLs that run arbitrary JavaScript in the user's browser when accessed.

  • CVE-2017-1000404MedJan 26, 2018
    risk 0.40cvss 6.1epss 0.01

    The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs.

  • CVE-2017-1000389MedJan 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could have been interpreted as HTML by clients, resulting in a potential reflected…

  • CVE-2017-1000109MedOct 5, 2017
    risk 0.40cvss 6.1epss 0.01

    The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.

  • CVE-2016-4988MedFeb 9, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.

  • CVE-2023-27899HigMar 10, 2023
    risk 0.39cvss 7.0epss 0.00

    Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file…

  • CVE-2022-20619HigJan 12, 2022
    risk 0.39cvss 7.1epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials…

  • CVE-2021-43577HigNov 12, 2021
    risk 0.39cvss 7.1epss 0.01

    Jenkins OWASP Dependency-Check Plugin 5.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2021-21680HigAug 31, 2021
    risk 0.39cvss 7.1epss 0.01

    Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) attacks.

  • CVE-2021-21656HigMay 11, 2021
    risk 0.39cvss 7.1epss 0.02

    Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2021-21655HigMay 11, 2021
    risk 0.39cvss 7.1epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified Perforce server using attacker-specified username and password.

  • CVE-2020-2144HigMar 9, 2020
    risk 0.39cvss 7.1epss 0.01

    Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2140MedMar 9, 2020
    risk 0.39cvss 6.1epss 0.76

    Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.

  • CVE-2020-2138HigMar 9, 2020
    risk 0.39cvss 7.1epss 0.01

    Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2019-1003044HigMar 28, 2019
    risk 0.39cvss 7.1epss 0.01

    A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2025-64135MedOct 29, 2025
    risk 0.38cvss 5.9epss 0.00

    Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value, disabling a protection mechanism of the Java runtime.

  • CVE-2025-47888MedMay 14, 2025
    risk 0.38cvss 5.9epss 0.00

    Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections to the configured DingTalk webhooks.

  • CVE-2023-40343MedAug 16, 2023
    risk 0.38cvss 5.9epss 0.01

    Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.

  • CVE-2020-2230MedAug 12, 2020
    risk 0.38cvss 5.4epss 0.83

    Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.

  • CVE-2019-10317MedApr 30, 2019
    risk 0.38cvss 5.9epss 0.01

    Jenkins SiteMonitor Plugin 0.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JVM.

  • CVE-2019-10314MedApr 30, 2019
    risk 0.38cvss 5.9epss 0.01

    Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM.

  • CVE-2018-1000173MedMay 8, 2018
    risk 0.38cvss 5.9epss 0.02

    A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.

  • CVE-2017-1000402MedJan 26, 2018
    risk 0.38cvss 5.9epss 0.00

    Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks.

  • CVE-2017-1000397MedJan 26, 2018
    risk 0.38cvss 5.9epss 0.00

    Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on…

  • CVE-2023-50770MedDec 13, 2023
    risk 0.37cvss 6.7epss 0.00

    Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that…

  • CVE-2022-34212MedJun 23, 2022
    risk 0.37cvss 5.7epss 0.01

    A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request to an attacker-specified URL.

  • CVE-2026-48927MedMay 27, 2026
    risk 0.36cvss 5.5epss 0.00

    Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.

  • CVE-2025-31728MedApr 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-31727MedApr 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2025-31726MedApr 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2025-31725MedApr 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2023-24454MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2023-24442MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins…

  • CVE-2023-24440MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2023-24439MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.00

    Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-45386MedNov 15, 2022
    risk 0.36cvss 5.5epss 0.00

    Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2021-21612MedJan 13, 2021
    risk 0.36cvss 5.5epss 0.00

    Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-2314MedNov 4, 2020
    risk 0.36cvss 5.5epss 0.00

    Jenkins AppSpider Plugin 1.0.12 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-2274MedSep 16, 2020
    risk 0.36cvss 5.5epss 0.00

    Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-2154MedMar 9, 2020
    risk 0.36cvss 5.5epss 0.00

    Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier stores its credentials in plain text in a global configuration file on the Jenkins master file system.

  • CVE-2020-2145MedMar 9, 2020
    risk 0.36cvss 5.5epss 0.00

    Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system.

  • CVE-2019-16572MedDec 17, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-16543MedNov 21, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10430MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

  • CVE-2019-10426MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins Gem Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10424MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins elOyente Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10423MedSep 25, 2019
    risk 0.36cvss 5.5epss 0.00

    Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

Page 16 of 38