VYPR

Vendor CVEs

Jenkins Project

All CVEs

1,869 total · sorted by risk
  • CVE-2016-0789MedApr 7, 2016
    risk 0.33cvss 6.1epss 0.02

    CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

  • CVE-2020-2231MedAug 12, 2020
    risk 0.32cvss 5.4epss 0.05

    Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the…

  • CVE-2020-2229MedAug 12, 2020
    risk 0.32cvss 5.4epss 0.07

    Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.

  • CVE-2026-57289MedJun 24, 2026
    risk 0.31cvss 4.8epss 0.00

    Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept…

  • CVE-2023-37943MedJul 12, 2023
    risk 0.31cvss 5.9epss 0.00

    Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory…

  • CVE-2023-32993MedMay 16, 2023
    risk 0.31cvss 4.8epss 0.00

    Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.

  • CVE-2022-25202MedFeb 15, 2022
    risk 0.31cvss 4.8epss 0.01

    Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name of custom promotion levels, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.

  • CVE-2020-2100MedJan 29, 2020
    risk 0.31cvss 5.8epss 0.03

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848.

  • CVE-2019-16546MedNov 21, 2019
    risk 0.31cvss 5.9epss 0.01

    Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.

  • CVE-2019-10349MedJul 11, 2019
    risk 0.31cvss 5.4epss 0.04

    A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.

  • CVE-2019-1003019MedFeb 6, 2019
    risk 0.31cvss 5.9epss 0.01

    An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.

  • CVE-2018-1000602MedJun 26, 2018
    risk 0.31cvss 5.9epss 0.01

    A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session.

  • CVE-2017-1000396MedJan 26, 2018
    risk 0.31cvss 5.9epss 0.01

    Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. This library is widely used as a transitive…

  • CVE-2018-1000015MedJan 23, 2018
    risk 0.31cvss 4.8epss 0.01

    On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline `node` blocks on those agents due to incorrect permissions checks in Pipeline:…

  • CVE-2017-17383MedDec 6, 2017
    risk 0.31cvss 4.7epss 0.01

    Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.

  • CVE-2023-24428MedJan 26, 2023
    risk 0.30cvss 5.7epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.

  • CVE-2022-41231MedSep 21, 2022
    risk 0.30cvss 5.7epss 0.01

    Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenkins controller file system by providing a crafted file name to an API endpoint.

  • CVE-2022-27195MedMar 15, 2022
    risk 0.29cvss 5.5epss 0.00

    Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files. These values are stored unencrypted and can be viewed by…

  • CVE-2022-20621MedJan 12, 2022
    risk 0.29cvss 5.5epss 0.00

    Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2021-21681MedAug 31, 2021
    risk 0.29cvss 5.5epss 0.00

    Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2021-21635MedMar 30, 2021
    risk 0.29cvss 5.4epss 0.09

    Jenkins REST List Parameter Plugin 1.3.0 and earlier does not escape a parameter name reference in embedded JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2021-21622MedFeb 24, 2021
    risk 0.29cvss 5.4epss 0.09

    Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2021-21616MedFeb 24, 2021
    risk 0.29cvss 4.6epss 0.79

    Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2021-21614MedJan 13, 2021
    risk 0.29cvss 5.5epss 0.00

    Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-2187MedMay 6, 2020
    risk 0.29cvss 5.6epss 0.00

    Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle attacks.

  • CVE-2020-2185MedMay 6, 2020
    risk 0.29cvss 5.6epss 0.01

    Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the-middle attacks.

  • CVE-2020-2103MedJan 29, 2020
    risk 0.29cvss 5.4epss 0.07

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.

  • CVE-2019-10429MedSep 25, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins GitLab Logo Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10398MedSep 12, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

  • CVE-2019-10367MedAug 7, 2019
    risk 0.29cvss 5.5epss 0.00

    Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging the configuration being applied.

  • CVE-2019-10364MedJul 31, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Amazon EC2 Plugin 1.43 and earlier wrote the beginning of private keys to the Jenkins system log.

  • CVE-2019-10361MedJul 31, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system.

  • CVE-2019-10345MedJul 31, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.

  • CVE-2018-1999041MedAug 1, 2018
    risk 0.29cvss 5.5epss 0.00

    An exposure of sensitive information vulnerability exists in Jenkins Tinfoil Security Plugin 1.6.1 and earlier in TinfoilScanRecorder.java that allows attackers with file system access to the Jenkins master to obtain the API secret key stored in this plugin's configuration.

  • CVE-2018-1000151MedApr 5, 2018
    risk 0.29cvss 5.6epss 0.00

    A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by default.

  • CVE-2018-1000149MedApr 5, 2018
    risk 0.29cvss 5.6epss 0.01

    A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, AnsibleAdHocCommandInvocationTest.java, AnsibleContext.java, AnsibleJobDslExtension.java, AnsiblePlaybookBuilder.java,…

  • CVE-2026-70445MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-70438MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-70436MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with…

  • CVE-2026-70433MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-57302MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Extended Read permission or access to the Jenkins controller file system.

  • CVE-2026-57300MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.

  • CVE-2026-57299MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.

  • CVE-2026-57297MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key.

  • CVE-2026-57293MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-57290MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier allows attackers to overwrite the global job priority configuration.

  • CVE-2026-57287MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers with Extended Read permission to view encrypted secret values that would…

  • CVE-2026-57286MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revision metadata.

  • CVE-2026-57285MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configuration.

  • CVE-2026-57284MedJun 24, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps.

Page 23 of 38