VYPR

Vendor CVEs

Jenkins Project

All CVEs

1,922 total · sorted by risk
  • CVE-2017-1000094MedOct 5, 2017
    risk 0.35cvss 6.5epss 0.01

    Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use to authenticate with a Docker Registry. This functionality did not check permissions, allowing any user with Overall/Read permission to get a…

  • CVE-2017-1000089MedOct 5, 2017
    risk 0.35cvss 5.3epss 0.01

    Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project…

  • CVE-2017-1000088MedOct 5, 2017
    risk 0.35cvss 5.4epss 0.01

    The Sidebar Link plugin allows users able to configure jobs, views, and agents to add entries to the sidebar of these objects. There was no input validation, which meant users were able to use javascript: schemes for these links.

  • CVE-2017-1000084MedOct 5, 2017
    risk 0.35cvss 6.5epss 0.01

    Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.

  • CVE-2016-4987MedFeb 9, 2017
    risk 0.35cvss 6.5epss 0.03

    Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified form fields.

  • CVE-2016-0790MedApr 7, 2016
    risk 0.35cvss 5.3epss 0.02

    Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.

  • CVE-2025-53743MedJul 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-53677MedJul 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2025-53674MedJul 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2025-53667MedJul 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-53655MedJul 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2024-43045MedAug 7, 2024
    risk 0.34cvss 6.3epss 0.03

    Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to access other users' "My Views".

  • CVE-2024-28152MedMar 6, 2024
    risk 0.34cvss 6.3epss 0.01

    In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" allows changes to Jenkinsfiles from users without write access to the project when…

  • CVE-2023-46660MedOct 25, 2023
    risk 0.34cvss 5.3epss 0.00

    Jenkins Zanata Plugin 0.6 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token hashes are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

  • CVE-2023-46658MedOct 25, 2023
    risk 0.34cvss 5.3epss 0.01

    Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

  • CVE-2023-46657MedOct 25, 2023
    risk 0.34cvss 5.3epss 0.01

    Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

  • CVE-2023-41934MedSep 6, 2023
    risk 0.34cvss 5.3epss 0.01

    Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentials specified in custom Maven settings in Pipeline build logs if "Treat username as secret" is checked.

  • CVE-2023-40349MedAug 16, 2023
    risk 0.34cvss 5.3epss 0.01

    Jenkins Gogs Plugin 1.0.15 and earlier improperly initializes an option to secure its webhook endpoint, allowing unauthenticated attackers to trigger builds of jobs.

  • CVE-2023-40348MedAug 16, 2023
    risk 0.34cvss 5.3epss 0.01

    The webhook endpoint in Jenkins Gogs Plugin 1.0.15 and earlier provides unauthenticated attackers information about the existence of jobs in its output.

  • CVE-2023-39156MedJul 26, 2023
    risk 0.34cvss 5.3epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Bazaar Plugin 1.22 and earlier allows attackers to delete previously created Bazaar SCM tags.

  • CVE-2023-39155MedJul 26, 2023
    risk 0.34cvss 5.3epss 0.01

    Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.

  • CVE-2023-30521MedApr 12, 2023
    risk 0.34cvss 5.3epss 0.01

    A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.

  • CVE-2023-30519MedApr 12, 2023
    risk 0.34cvss 5.3epss 0.00

    A missing permission check in Jenkins Quay.io trigger Plugin 0.1 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.

  • CVE-2023-30517MedApr 12, 2023
    risk 0.34cvss 5.3epss 0.00

    Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier unconditionally disables SSL/TLS certificate and hostname validation when connecting to a configured NeuVector Vulnerability Scanner server.

  • CVE-2022-45389MedNov 15, 2022
    risk 0.34cvss 5.3epss 0.01

    A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an attacker-specified repository.

  • CVE-2022-43435MedOct 19, 2022
    risk 0.34cvss 5.3epss 0.01

    Jenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

  • CVE-2022-43426MedOct 19, 2022
    risk 0.34cvss 5.3epss 0.01

    Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potential for attackers to observe and capture it.

  • CVE-2022-43412MedOct 19, 2022
    risk 0.34cvss 5.3epss 0.01

    Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

  • CVE-2022-41248MedSep 21, 2022
    risk 0.34cvss 5.3epss 0.00

    Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2022-41235MedSep 21, 2022
    risk 0.34cvss 5.3epss 0.01

    Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.

  • CVE-2022-34777MedJun 30, 2022
    risk 0.34cvss 5.4epss 0.73

    Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-triggered builds, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2022-34176MedJun 23, 2022
    risk 0.34cvss 5.4epss 0.78

    Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.

  • CVE-2021-21667MedJun 16, 2021
    risk 0.34cvss 5.4epss 0.76

    Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.

  • CVE-2021-21649MedMay 11, 2021
    risk 0.34cvss 5.4epss 0.73

    Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.

  • CVE-2021-21648MedMay 11, 2021
    risk 0.34cvss 6.1epss 0.11

    Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulting in a reflected cross-site scripting (XSS) vulnerability.

  • CVE-2021-21630MedMar 30, 2021
    risk 0.34cvss 5.4epss 0.72

    Jenkins Extra Columns Plugin 1.22 and earlier does not escape parameter values in the build parameters column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2020-2155MedMar 9, 2020
    risk 0.34cvss 5.3epss 0.01

    Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2020-2150MedMar 9, 2020
    risk 0.34cvss 5.3epss 0.01

    Jenkins Sonar Quality Gates Plugin 1.3.1 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2020-2149MedMar 9, 2020
    risk 0.34cvss 5.3epss 0.01

    Jenkins Repository Connector Plugin 1.2.6 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2019-16568MedDec 17, 2019
    risk 0.34cvss 5.3epss 0.01

    Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of the global configuration, as well as individual jobs' configurations.

  • CVE-2019-10378MedAug 7, 2019
    risk 0.34cvss 5.3epss 0.01

    Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10359MedJul 31, 2019
    risk 0.34cvss 6.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doSubmit method allowed attackers to perform releases with attacker-specified options.

  • CVE-2023-50771MedDec 13, 2023
    risk 0.33cvss 6.1epss 0.01

    Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.

  • CVE-2023-3414MedJul 26, 2023
    risk 0.33cvss 6.1epss 0.00

    A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins…

  • CVE-2022-46683MedDec 12, 2022
    risk 0.33cvss 6.1epss 0.01

    Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkins.

  • CVE-2022-36922MedJul 27, 2022
    risk 0.33cvss 6.1epss 0.01

    Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page, resulting in a reflected cross-site scripting (XSS) vulnerability.

  • CVE-2022-34182MedJun 23, 2022
    risk 0.33cvss 6.1epss 0.01

    Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.

  • CVE-2022-34178MedJun 23, 2022
    risk 0.33cvss 6.1epss 0.01

    Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability.

  • CVE-2021-21684MedOct 6, 2021
    risk 0.33cvss 6.1epss 0.01

    Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.

  • CVE-2021-21673MedJun 30, 2021
    risk 0.33cvss 6.1epss 0.02

    Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.

Page 23 of 39