VYPR

Vendor CVEs

Jenkins Project

All CVEs

1,922 total · sorted by risk
  • CVE-2021-21666MedJun 10, 2021
    risk 0.33cvss 6.1epss 0.01

    Jenkins Kiuwan Plugin 1.6.0 and earlier does not escape query parameters in an error message for a form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.

  • CVE-2021-21613MedJan 13, 2021
    risk 0.33cvss 6.1epss 0.01

    Jenkins TICS Plugin 2020.3.0.6 and earlier does not escape TICS service responses, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control TICS service response content.

  • CVE-2021-21610MedJan 13, 2021
    risk 0.33cvss 6.1epss 0.01

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted preview of markup passed as a query parameter, resulting in a reflected cross-site scripting (XSS) vulnerability if the configured markup formatter does not…

  • CVE-2020-2207MedJul 2, 2020
    risk 0.33cvss 6.1epss 0.01

    Jenkins VncViewer Plugin 1.7 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.

  • CVE-2020-2169MedMar 25, 2020
    risk 0.33cvss 6.1epss 0.01

    A form validation endpoint in Jenkins Queue cleanup Plugin 1.3 and earlier does not properly escape a query parameter displayed in an error message, resulting in a reflected XSS vulnerability.

  • CVE-2012-4441MedNov 18, 2019
    risk 0.33cvss 6.1epss 0.02

    Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.

  • CVE-2012-4440MedNov 18, 2019
    risk 0.33cvss 6.1epss 0.02

    Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.

  • CVE-2019-10405MedSep 25, 2019
    risk 0.33cvss 5.4epss 0.65

    Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers exploiting another XSS vulnerability to obtain the HTTP session cookie despite it being marked HttpOnly.

  • CVE-2019-10372MedAug 7, 2019
    risk 0.33cvss 6.1epss 0.01

    An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users to a URL outside Jenkins after successful login.

  • CVE-2019-10336MedJun 11, 2019
    risk 0.33cvss 6.1epss 0.01

    A reflected cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.6 and earlier allowed attackers able to control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in job configuration forms containing post-build steps provided by this…

  • CVE-2018-1000416MedJan 9, 2019
    risk 0.33cvss 6.1epss 0.01

    A reflected cross-site scripting vulnerability exists in Jenkins Job Config History Plugin 2.18 and earlier in all Jelly files that shows arbitrary attacker-specified HTML in Jenkins to users with Job/Configure access.

  • CVE-2018-1000407MedJan 9, 2019
    risk 0.33cvss 6.1epss 0.02

    A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by Jenkins.

  • CVE-2016-0789MedApr 7, 2016
    risk 0.33cvss 6.1epss 0.02

    CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

  • CVE-2020-2231MedAug 12, 2020
    risk 0.32cvss 5.4epss 0.05

    Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the…

  • CVE-2020-2229MedAug 12, 2020
    risk 0.32cvss 5.4epss 0.07

    Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.

  • CVE-2023-37943MedJul 12, 2023
    risk 0.31cvss 5.9epss 0.00

    Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory…

  • CVE-2023-32993MedMay 16, 2023
    risk 0.31cvss 4.8epss 0.00

    Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.

  • CVE-2022-25202MedFeb 15, 2022
    risk 0.31cvss 4.8epss 0.01

    Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name of custom promotion levels, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.

  • CVE-2020-2205MedJul 2, 2020
    risk 0.31cvss 4.8epss 0.01

    Jenkins VncRecorder Plugin 1.25 and earlier does not escape a tool path in the `checkVncServ` form validation endpoint, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by Jenkins administrators.

  • CVE-2020-2100MedJan 29, 2020
    risk 0.31cvss 5.8epss 0.03

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848.

  • CVE-2019-16546MedNov 21, 2019
    risk 0.31cvss 5.9epss 0.01

    Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by the plugin, enabling man-in-the-middle attacks.

  • CVE-2019-10349MedJul 11, 2019
    risk 0.31cvss 5.4epss 0.04

    A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.

  • CVE-2019-1003019MedFeb 6, 2019
    risk 0.31cvss 5.9epss 0.01

    An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm.java that allows unauthorized attackers to impersonate another user if they can control the pre-authentication session.

  • CVE-2018-1000602MedJun 26, 2018
    risk 0.31cvss 5.9epss 0.01

    A session fixation vulnerability exists in Jenkins SAML Plugin 1.0.6 and earlier in SamlSecurityRealm.java that allows unauthorized attackers to impersonate another users if they can control the pre-authentication session.

  • CVE-2017-1000396MedJan 26, 2018
    risk 0.31cvss 5.9epss 0.01

    Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. This library is widely used as a transitive…

  • CVE-2018-1000015MedJan 23, 2018
    risk 0.31cvss 4.8epss 0.01

    On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents. This did not prevent the execution of Pipeline `node` blocks on those agents due to incorrect permissions checks in Pipeline:…

  • CVE-2017-17383MedDec 6, 2017
    risk 0.31cvss 4.7epss 0.01

    Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.

  • CVE-2023-24428MedJan 26, 2023
    risk 0.30cvss 5.7epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.

  • CVE-2022-41231MedSep 21, 2022
    risk 0.30cvss 5.7epss 0.01

    Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenkins controller file system by providing a crafted file name to an API endpoint.

  • CVE-2022-27195MedMar 15, 2022
    risk 0.29cvss 5.5epss 0.00

    Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files. These values are stored unencrypted and can be viewed by…

  • CVE-2022-20621MedJan 12, 2022
    risk 0.29cvss 5.5epss 0.00

    Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2021-21681MedAug 31, 2021
    risk 0.29cvss 5.5epss 0.00

    Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2021-21635MedMar 30, 2021
    risk 0.29cvss 5.4epss 0.09

    Jenkins REST List Parameter Plugin 1.3.0 and earlier does not escape a parameter name reference in embedded JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2021-21622MedFeb 24, 2021
    risk 0.29cvss 5.4epss 0.09

    Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2021-21616MedFeb 24, 2021
    risk 0.29cvss 4.6epss 0.79

    Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2021-21614MedJan 13, 2021
    risk 0.29cvss 5.5epss 0.00

    Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-2187MedMay 6, 2020
    risk 0.29cvss 5.6epss 0.00

    Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle attacks.

  • CVE-2020-2185MedMay 6, 2020
    risk 0.29cvss 5.6epss 0.01

    Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the-middle attacks.

  • CVE-2020-2103MedJan 29, 2020
    risk 0.29cvss 5.4epss 0.07

    Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.

  • CVE-2019-10429MedSep 25, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins GitLab Logo Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10398MedSep 12, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

  • CVE-2019-10367MedAug 7, 2019
    risk 0.29cvss 5.5epss 0.00

    Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expected to be hidden when logging the configuration being applied.

  • CVE-2019-10364MedJul 31, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Amazon EC2 Plugin 1.43 and earlier wrote the beginning of private keys to the Jenkins system log.

  • CVE-2019-10361MedJul 31, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system.

  • CVE-2019-10345MedJul 31, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.

  • CVE-2018-1999041MedAug 1, 2018
    risk 0.29cvss 5.5epss 0.00

    An exposure of sensitive information vulnerability exists in Jenkins Tinfoil Security Plugin 1.6.1 and earlier in TinfoilScanRecorder.java that allows attackers with file system access to the Jenkins master to obtain the API secret key stored in this plugin's configuration.

  • CVE-2018-1000151MedApr 5, 2018
    risk 0.29cvss 5.6epss 0.00

    A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by default.

  • CVE-2018-1000149MedApr 5, 2018
    risk 0.29cvss 5.6epss 0.01

    A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, AnsibleAdHocCommandInvocationTest.java, AnsibleContext.java, AnsibleJobDslExtension.java, AnsiblePlaybookBuilder.java,…

  • CVE-2026-92141MedSep 16, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

  • CVE-2026-84676MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

Page 24 of 39