VYPR

Vendor CVEs

Jenkins Project

All CVEs

1,869 total · sorted by risk
  • CVE-2025-59476MedSep 17, 2025
    risk 0.00cvss 5.3epss 0.00

    Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log…

  • CVE-2025-59475MedSep 17, 2025
    risk 0.00cvss 4.3epss 0.00

    Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options…

  • CVE-2025-53653MedJul 9, 2025
    risk 0.00cvss 4.3epss 0.00

    Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2025-53652HigJul 9, 2025
    risk 0.00cvss 8.2epss 0.01

    Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.

  • CVE-2025-53651MedJul 9, 2025
    risk 0.00cvss 6.3epss 0.00

    Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths of files archived during the Publish HTML reports post-build step, exposing information about the Jenkins controller file system in the build log.

  • CVE-2025-53650HigJul 9, 2025
    risk 0.00cvss 7.3epss 0.00

    Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to the build log.

  • CVE-2025-24400MedJan 22, 2025
    risk 0.00cvss 4.3epss 0.00

    Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event…

  • CVE-2025-24398HigJan 22, 2025
    risk 0.00cvss 8.8epss 0.00

    Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.

  • CVE-2025-24397MedJan 22, 2025
    risk 0.00cvss 4.3epss 0.00

    An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in…

  • CVE-2024-52554HigNov 13, 2024
    risk 0.00cvss 8.8epss 0.01

    Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to configure a…

  • CVE-2024-52553HigNov 13, 2024
    risk 0.00cvss 8.8epss 0.01

    Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.

  • CVE-2024-52551HigNov 13, 2024
    risk 0.00cvss 8.0epss 0.01

    Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose…

  • CVE-2024-52550HigNov 13, 2024
    risk 0.00cvss 8.0epss 0.00

    Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile)…

  • CVE-2024-52549MedNov 13, 2024
    risk 0.00cvss 4.3epss 0.00

    Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the…

  • CVE-2024-2216HigMar 6, 2024
    risk 0.00cvss 8.8epss 0.01

    A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test…

  • CVE-2024-2215MedMar 6, 2024
    risk 0.00cvss 6.1epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build…

  • CVE-2023-46656MedOct 25, 2023
    risk 0.00cvss 5.3epss 0.01

    Jenkins Multibranch Scan Webhook Trigger Plugin 1.0.9 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.

  • CVE-2022-45392MedNov 15, 2022
    risk 0.00cvss 6.5epss 0.01

    Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2022-45391HigNov 15, 2022
    risk 0.00cvss 7.5epss 0.00

    Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.

  • CVE-2022-38666HigNov 15, 2022
    risk 0.00cvss 7.5epss 0.00

    Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for several features.

  • CVE-2022-43418MedOct 19, 2022
    risk 0.00cvss 4.3epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2022-43417MedOct 19, 2022
    risk 0.00cvss 4.3epss 0.01

    Jenkins Katalon Plugin 1.0.32 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing…

  • CVE-2022-41228HigSep 21, 2022
    risk 0.00cvss 8.8epss 0.01

    A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to connect to an attacker-specified webserver using attacker-specified credentials.

  • CVE-2022-41227HigSep 21, 2022
    risk 0.00cvss 8.8epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials.

  • CVE-2022-36899HigJul 27, 2022
    risk 0.00cvss 8.2epss 0.01

    Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able to control agent processes to retrieve Java system properties.

  • CVE-2022-36889HigJul 27, 2022
    risk 0.00cvss 8.8epss 0.02

    Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the…

  • CVE-2022-34781MedJun 30, 2022
    risk 0.00cvss 6.5epss 0.01

    Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored…

  • CVE-2022-34780MedJun 30, 2022
    risk 0.00cvss 6.5epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in…

  • CVE-2022-34779MedJun 30, 2022
    risk 0.00cvss 4.3epss 0.01

    A missing permission check in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-34189MedJun 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2022-34185MedJun 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2022-30963MedMay 17, 2022
    risk 0.00cvss 5.4epss 0.01

    Jenkins JDK Parameter Plugin 1.0 and earlier does not escape the name and description of JDK parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2022-27212MedMar 15, 2022
    risk 0.00cvss 5.4epss 0.01

    Jenkins List Git Branches Parameter Plugin 0.0.9 and earlier does not escape the name of the 'List Git branches (and more)' parameter, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2022-25196MedFeb 15, 2022
    risk 0.00cvss 5.4epss 0.01

    Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect users to an attacker-specified URL after…

  • CVE-2022-23117HigJan 12, 2022
    risk 0.00cvss 7.5epss 0.01

    Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.

  • CVE-2022-23107HigJan 12, 2022
    risk 0.00cvss 8.1epss 0.02

    Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system.

  • CVE-2021-21701MedNov 12, 2021
    risk 0.00cvss 6.5epss 0.02

    Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2021-21687CriNov 4, 2021
    risk 0.00cvss 9.1epss 0.01

    Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic link in FilePath#untar.

  • CVE-2021-21676MedJun 30, 2021
    risk 0.00cvss 4.3epss 0.01

    Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address.

  • CVE-2021-21675MedJun 30, 2021
    risk 0.00cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or have administrators apply pending requests.

  • CVE-2021-21665HigJun 10, 2021
    risk 0.00cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials…

  • CVE-2021-21663MedJun 10, 2021
    risk 0.00cvss 4.3epss 0.01

    A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 7.5.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password…

  • CVE-2021-21652HigMay 11, 2021
    risk 0.00cvss 7.1epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored…

  • CVE-2021-21620MedFeb 24, 2021
    risk 0.00cvss 4.3epss 0.02

    A cross-site request forgery (CSRF) vulnerability in Jenkins Claim Plugin 2.18.1 and earlier allows attackers to change claims.

  • CVE-2020-2323MedDec 3, 2020
    risk 0.00cvss 5.3epss 0.01

    Jenkins Chaos Monkey Plugin 0.4 and earlier does not perform permission checks in an HTTP endpoint, allowing attackers with Overall/Read permission to access the Chaos Monkey page and to see the history of actions.

  • CVE-2020-2322HigDec 3, 2020
    risk 0.00cvss 7.5epss 0.01

    Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks.

  • CVE-2020-2275MedSep 16, 2020
    risk 0.00cvss 6.5epss 0.02

    Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.

  • CVE-2020-2235MedAug 12, 2020
    risk 0.00cvss 6.5epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows attackers to connect to an attacker-specified JDBC URL using attacker-specified credentials IDs obtained through another method, potentially capturing…

  • CVE-2020-2234MedAug 12, 2020
    risk 0.00cvss 6.5epss 0.01

    A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to connect to an attacker-specified JDBC URL using attacker-specified credentials IDs obtained through another method, potentially capturing…

  • CVE-2020-2233MedAug 12, 2020
    risk 0.00cvss 6.5epss 0.01

    A missing permission check in Jenkins Pipeline Maven Integration Plugin 3.8.2 and earlier allows users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.