VYPR

Vendor CVEs

Jenkins Project

All CVEs

1,922 total · sorted by risk
  • CVE-2022-23115MedJan 12, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site request forgery (CSRF) vulnerabilities in Jenkins batch task Plugin 1.19 and earlier allows attackers with Overall/Read access to retrieve logs, build or delete a batch task.

  • CVE-2022-23106MedJan 12, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.

  • CVE-2021-21700MedNov 12, 2021
    risk 0.28cvss 5.4epss 0.01

    Jenkins Scriptler Plugin 3.3 and earlier does not escape the name of scripts on the UI when asking to confirm their deletion, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by exploitable by attackers able to create Scriptler scripts.

  • CVE-2021-21661MedJun 10, 2021
    risk 0.28cvss 4.3epss 0.02

    Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2021-21660MedMay 25, 2021
    risk 0.28cvss 5.4epss 0.01

    Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to edit any description rendered using the configured markup formatter.

  • CVE-2021-21653MedMay 11, 2021
    risk 0.28cvss 4.3epss 0.01

    Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier does not perform a permission check in an HTTP endpoint, allowing with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2021-21644MedApr 21, 2021
    risk 0.28cvss 5.4epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID.

  • CVE-2021-21636MedMar 30, 2021
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2021-21626MedMar 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Jenkins Warnings Next Generation Plugin 8.4.4 and earlier does not perform a permission check in methods implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file…

  • CVE-2021-21621MedFeb 24, 2021
    risk 0.28cvss 5.3epss 0.01

    Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (basic authentication details only)" information, which can include the session ID of the user creating the support bundle in some configurations.

  • CVE-2021-21611MedJan 13, 2021
    risk 0.28cvss 5.4epss 0.01

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names or IDs of item types.

  • CVE-2021-21609MedJan 13, 2021
    risk 0.28cvss 5.3epss 0.01

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did have Overall/Read permission.

  • CVE-2021-21608MedJan 13, 2021
    risk 0.28cvss 5.4epss 0.01

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to control button labels.

  • CVE-2021-21603MedJan 13, 2021
    risk 0.28cvss 5.4epss 0.01

    Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vulnerability.

  • CVE-2020-2296MedOct 8, 2020
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Shared Objects Plugin 0.44 and earlier allows attackers to configure shared objects.

  • CVE-2020-2292MedOct 8, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Release/Release permission.

  • CVE-2020-2290MedOct 8, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Active Choices Plugin 2.4 and earlier does not escape some return values of sandboxed scripts for Reactive Reference Parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2020-2289MedOct 8, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Active Choices Plugin 2.4 and earlier does not escape the name and description of build parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2020-2288MedOct 8, 2020
    risk 0.28cvss 5.3epss 0.01

    In Jenkins Audit Trail Plugin 3.6 and earlier, the default regular expression pattern could be bypassed in many cases by adding a suffix to the URL that would be ignored during request handling.

  • CVE-2020-2287MedOct 8, 2020
    risk 0.28cvss 5.3epss 0.01

    Jenkins Audit Trail Plugin 3.6 and earlier applies pattern matching to a different representation of request URL paths than the Stapler web framework uses for dispatching requests, which allows attackers to craft URLs that bypass request logging of any target URL.

  • CVE-2020-2283MedSep 23, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control changeset files evaluated by the plugin.

  • CVE-2020-2281MedSep 23, 2020
    risk 0.28cvss 5.4epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Lockable Resources Plugin 2.8 and earlier allows attackers to reserve, unreserve, unlock, and reset resources.

  • CVE-2020-2273MedSep 16, 2020
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2020-2272MedSep 16, 2020
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2020-2267MedSep 16, 2020
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins MongoDB Plugin 1.3 and earlier allows attackers with Overall/Read permission to gain access to some metadata of any arbitrary files on the Jenkins controller.

  • CVE-2020-2260MedSep 16, 2020
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Perfecto Plugin 1.17 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.

  • CVE-2020-2259MedSep 16, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

  • CVE-2020-2257MedSep 16, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Validating String Parameter Plugin 2.4 and earlier does not escape various user-controlled fields, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2020-2256MedSep 16, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Pipeline Maven Integration Plugin 3.9.2 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2020-2251MedSep 1, 2020
    risk 0.28cvss 4.3epss 0.01

    Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.

  • CVE-2020-2244MedSep 1, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to provide console output for builds used to test build log indications.

  • CVE-2020-2238MedSep 1, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

  • CVE-2020-2237MedAug 12, 2020
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Flaky Test Handler Plugin 1.0.4 and earlier allows attackers to rebuild a project at a previous git revision.

  • CVE-2020-2236MedAug 12, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission.

  • CVE-2020-2227MedJul 15, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Deployer Framework Plugin 1.2 and earlier does not escape the URL displayed in the build home page, resulting in a stored cross-site scripting vulnerability.

  • CVE-2020-2226MedJul 15, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability.

  • CVE-2020-2225MedJul 15, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerability.

  • CVE-2020-2224MedJul 15, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site scripting vulnerability.

  • CVE-2020-2223MedJul 15, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.

  • CVE-2020-2222MedJul 15, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.

  • CVE-2020-2221MedJul 15, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.

  • CVE-2020-2220MedJul 15, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.

  • CVE-2020-2216MedJul 2, 2020
    risk 0.28cvss 4.3epss 0.01

    A missing permission check in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified username and password.

  • CVE-2020-2215MedJul 2, 2020
    risk 0.28cvss 4.3epss 0.01

    A cross-site request forgery vulnerability in Jenkins Zephyr for JIRA Test Management Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified username and password.

  • CVE-2020-2214MedJul 2, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins ZAP Pipeline Plugin 1.9 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

  • CVE-2020-2212MedJul 2, 2020
    risk 0.28cvss 4.3epss 0.01

    Jenkins GitHub Coverage Reporter Plugin 1.8 and earlier stores secrets unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system or read permissions on the system configuration.

  • CVE-2020-2210MedJul 2, 2020
    risk 0.28cvss 4.3epss 0.01

    Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.

  • CVE-2020-2208MedJul 2, 2020
    risk 0.28cvss 4.3epss 0.01

    Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2020-2204MedJul 2, 2020
    risk 0.28cvss 5.4epss 0.01

    A missing permission check in Jenkins Fortify on Demand Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to the globally configured Fortify on Demand endpoint using attacker-specified credentials IDs.

  • CVE-2020-2195MedJun 3, 2020
    risk 0.28cvss 5.4epss 0.01

    Jenkins Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips, resulting in a stored cross-site scripting vulnerability that can be exploited by users with Job/Configure permission.

Page 29 of 39