Skip to main content

Vendor/product archive

jenkins / github CVEs

Beta · best-effort

6 CVEs tagged to jenkins / github1 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-42523

Published Apr 29, 2026

Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm poll…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-46650

Published Oct 25, 2023

Jenkins GitHub Plugin 1.37.3 and earlier does not escape the GitHub project URL on the build page when showing changes, resulting in a stored cross-site scripting (XSS) vulnerabil…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36885

Published Jul 27, 2022

Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attack…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000600

Published Jun 26, 2018

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-spe…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-1000184

Published Jun 5, 2018

A server-side request forgery vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubPluginConfig.java that allows attackers with Overall/Read access to cause Jen…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000183

Published Jun 5, 2018

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers with Overall/Read access to con…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1