VYPR

Vendor CVEs

Jenkins Project

All CVEs

1,922 total · sorted by risk
  • CVE-2018-1000192MedJun 5, 2018
    risk 0.21cvss 4.3epss 0.01

    A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.

  • CVE-2018-1000185MedJun 5, 2018
    risk 0.21cvss 4.3epss 0.01

    A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.

  • CVE-2017-2598MedMay 23, 2018
    risk 0.21cvss 4.3epss 0.01

    Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).

  • CVE-2017-2609MedMay 22, 2018
    risk 0.21cvss 4.3epss 0.02

    jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autocomplete feature on the search box discloses the names of the views in its suggestions, including the ones for which the current user does…

  • CVE-2017-2604MedMay 15, 2018
    risk 0.21cvss 4.3epss 0.01

    In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not being consistently protected by permission checks (SECURITY-371).

  • CVE-2017-2600MedMay 15, 2018
    risk 0.21cvss 4.3epss 0.01

    In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of these nodes (SECURITY-343).

  • CVE-2017-2606MedMay 8, 2018
    risk 0.21cvss 4.3epss 0.02

    Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that should not be visible (SECURITY-380). This only affects anonymous users (other users legitimately have access) that were able to get a list of…

  • CVE-2017-2611MedMay 8, 2018
    risk 0.21cvss 4.3epss 0.02

    Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins to trigger these…

  • CVE-2018-1000150LowApr 5, 2018
    risk 0.21cvss 3.3epss 0.00

    An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users.

  • CVE-2018-1000109MedMar 13, 2018
    risk 0.21cvss 4.3epss 0.01

    An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs.

  • CVE-2018-1000105MedMar 13, 2018
    risk 0.21cvss 4.3epss 0.01

    An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to retrieve some configuration information about Gerrit in Jenkins.

  • CVE-2018-1000057MedFeb 9, 2018
    risk 0.21cvss 4.3epss 0.01

    Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to…

  • CVE-2017-1000400MedJan 26, 2018
    risk 0.21cvss 4.3epss 0.01

    The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This…

  • CVE-2017-1000399MedJan 26, 2018
    risk 0.21cvss 4.3epss 0.01

    The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in the queue (typically builds waiting to start). This included information about tasks that the current user otherwise has no access to, e.g. due to lack of…

  • CVE-2017-1000398MedJan 26, 2018
    risk 0.21cvss 4.3epss 0.01

    The remote API in Jenkins 2.73.1 and earlier, 2.83 and earlier at /computer/(agent-name)/api showed information about tasks (typically builds) currently running on that agent. This included information about tasks that the current user otherwise has no access to, e.g. due to…

  • CVE-2017-1000395MedJan 26, 2018
    risk 0.21cvss 4.3epss 0.01

    Jenkins 2.73.1 and earlier, 2.83 and earlier provides information about Jenkins user accounts which is generally available to anyone with Overall/Read permissions via the /user/(username)/api remote API. This included e.g. Jenkins users' email addresses if the Mailer Plugin is…

  • CVE-2016-3727MedMay 17, 2016
    risk 0.21cvss 4.3epss 0.02

    The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.

  • CVE-2026-92130LowSep 16, 2026
    risk 0.20cvss 3.1epss 0.00

    Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials lookup in the resolveScm Pipeline step, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

  • CVE-2025-58460MedSep 3, 2025
    risk 0.20cvss 4.2epss 0.00

    A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b_92b_cd64 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials…

  • CVE-2024-28162MedMar 6, 2024
    risk 0.20cvss 4.2epss 0.00

    In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections fails to take effect until Jenkins is restarted when switching from disabled validation…

  • CVE-2023-4777LowSep 8, 2023
    risk 0.20cvss 3.1epss 0.00

    An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins…

  • CVE-2023-4302MedAug 21, 2023
    risk 0.20cvss 4.2epss 0.00

    A missing permission check in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2023-4301MedAug 21, 2023
    risk 0.20cvss 4.2epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Fortify Plugin 22.1.38 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2019-10400MedSep 12, 2019
    risk 0.20cvss 4.2epss 0.01

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of subexpressions in increment and decrement expressions not involving actual assignment allowed attackers to execute arbitrary code in sandboxed scripts.

  • CVE-2019-10399MedSep 12, 2019
    risk 0.20cvss 4.2epss 0.01

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property names in property expressions in increment and decrement expressions allowed attackers to execute arbitrary code in sandboxed scripts.

  • CVE-2019-10397LowSep 12, 2019
    risk 0.20cvss 3.1epss 0.01

    Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure.

  • CVE-2019-10394MedSep 12, 2019
    risk 0.20cvss 4.2epss 0.01

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property names in property expressions on the left-hand side of assignment expressions allowed attackers to execute arbitrary code in sandboxed scripts.

  • CVE-2019-10393MedSep 12, 2019
    risk 0.20cvss 4.2epss 0.01

    A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of method names in method call expressions allowed attackers to execute arbitrary code in sandboxed scripts.

  • CVE-2018-1999038MedAug 1, 2018
    risk 0.20cvss 4.2epss 0.01

    A confused deputy vulnerability exists in Jenkins Publisher Over CIFS Plugin 0.10 and earlier in CifsPublisherPluginDescriptor.java that allows attackers to have Jenkins connect to an attacker specified CIFS server with attacker specified credentials.

  • CVE-2017-2607MedMay 21, 2018
    risk 0.20cvss 4.2epss 0.01

    jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting vulnerability in console notes (SECURITY-382). Jenkins allows plugins to annotate build logs, adding new content or changing the presentation of existing content while the build is running.…

  • CVE-2017-1000114LowOct 5, 2017
    risk 0.20cvss 3.1epss 0.01

    The Datadog Plugin stores an API key to access the Datadog service in the global Jenkins configuration. While the API key is stored encrypted on disk, it was transmitted in plain text as part of the configuration form. This could result in exposure of the API key for example…

  • CVE-2026-70430LowAug 5, 2026
    risk 0.18cvss 2.7epss 0.00

    Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration,…

  • CVE-2023-49652LowNov 29, 2023
    risk 0.18cvss 2.7epss 0.01

    Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate system-scoped credentials IDs of credentials…

  • CVE-2026-57288LowJun 24, 2026
    risk 0.17cvss 3.7epss 0.00

    Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries and to…

  • CVE-2025-0148LowFeb 3, 2025
    risk 0.17cvss 2.6epss 0.00

    Missing password field masking in the Zoom Jenkins Marketplace plugin before version 1.6 may allow an unauthenticated user to conduct a disclosure of information via adjacent network access.

  • CVE-2017-2651LowJul 27, 2018
    risk 0.17cvss 3.7epss 0.02

    jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result in emails being sent to people who have no user account in…

  • CVE-2025-67639LowDec 10, 2025
    risk 0.16cvss 3.5epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account.

  • CVE-2022-23114LowJan 12, 2022
    risk 0.14cvss 3.3epss 0.00

    Jenkins Publish Over SSH Plugin 1.22 and earlier stores password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2019-10433LowOct 1, 2019
    risk 0.14cvss 3.3epss 0.00

    Jenkins Dingding[钉钉] Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-10343LowJul 31, 2019
    risk 0.14cvss 3.3epss 0.00

    Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden when logging the configuration being applied.

  • CVE-2017-1000242LowNov 1, 2017
    risk 0.14cvss 3.3epss 0.00

    Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure

  • CVE-2025-30197LowMar 19, 2025
    risk 0.13cvss 3.1epss 0.00

    Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it.

  • CVE-2024-39458LowJun 26, 2024
    risk 0.13cvss 3.1epss 0.00

    When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message containing diagnostic information that may contain secrets passed as step parameters, potentially resulting in accidental exposure of secrets through the…

  • CVE-2017-2602LowMay 15, 2018
    risk 0.13cvss 3.1epss 0.02

    jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the agent-to-master security subsystem. This could allow metadata files to be written to by malicious agents (SECURITY-358).

  • CVE-2017-2603LowMay 15, 2018
    risk 0.10cvss 2.6epss 0.01

    Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).

  • CVE-2017-1000401LowJan 26, 2018
    risk 0.07cvss 2.2epss 0.00

    The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, <f:password/>, supports form validation (e.g. for API keys). The form validation AJAX requests were sent via GET, which could result in secrets being logged to a HTTP access…

  • CVE-2024-28156MedMar 6, 2024
    risk 0.06cvss 5.4epss 0.80

    Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure Build Monitor Views.

  • CVE-2024-34144CriMay 2, 2024
    risk 0.04cvss 9.8epss 0.48

    A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary…

  • CVE-1999-0060Mar 16, 1998
    risk 0.04cvss —epss 0.09

    Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool.

  • CVE-2013-5573Dec 31, 2013
    risk 0.03cvss —epss 0.05

    Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web script or HTML via the Description field in the user configuration.

Page 36 of 39