Skip to main content

Vendor archive

jenkins CVEs

Beta · best-effort

1,797 CVEs tagged to vendor jenkins78 Critical, 476 High, 1,209 Medium, 34 Low, 0 Unrated.

CVE-2018-1000183

Published Jun 5, 2018

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers with Overall/Read access to con…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000182

Published Jun 5, 2018

A server-side request forgery vulnerability exists in Jenkins Git Plugin 3.9.0 and older in AssemblaWeb.java, GitBlitRepositoryBrowser.java, Gitiles.java, TFS2013GitRepositoryBrow…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2598

Published May 23, 2018

Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (S…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2609

Published May 22, 2018

jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autocomplete feature on the search box disc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2607

Published May 21, 2018

jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting vulnerability in console notes (SECURITY-382). Jenkins allows plugins to annotate build logs…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2613

Published May 15, 2018

jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record was only retained until restart in most cases, administrator…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2610

Published May 15, 2018

jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in search suggestions due to improperly escaping users with less-than and greater-than chara…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2604

Published May 15, 2018

In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not being consistently protected by permission checks (SECURITY…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2603

Published May 15, 2018

Jenkins before versions 2.44, 2.32.2 is vulnerable to a user data leak in disconnected agents' config.xml API. This could leak sensitive data such as API tokens (SECURITY-362).

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-2602

Published May 15, 2018

jenkins before versions 2.44, 2.32.2 is vulnerable to an improper blacklisting of the Pipeline metadata files in the agent-to-master security subsystem. This could allow metadata…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-2612

Published May 15, 2018

In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds possibly failing to download…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2608

Published May 15, 2018

Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserialization of various types in javax.imageio in XStream-based APIs (…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-2600

Published May 15, 2018

In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2601

Published May 10, 2018

Jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in parameter names and descriptions (SECURITY-353). Users with the permission to configure j…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2606

Published May 8, 2018

Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that should not be visible (SECURITY-380). This…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2611

Published May 8, 2018

Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup di…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000177

Published May 8, 2018

A cross-site scripting vulnerability exists in Jenkins S3 Plugin 0.10.12 and older in src/main/resources/hudson/plugins/s3/S3ArtifactsProjectAction/jobMain.jelly that allows attac…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000176

Published May 8, 2018

An exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/emailext/ExtendedEmailPublisher/glo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000175

Published May 8, 2018

A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000174

Published May 8, 2018

An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL af…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000173

Published May 8, 2018

A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another u…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000170

Published Apr 16, 2018

A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Config…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000169

Published Apr 16, 2018

An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler.java that allows unauthorized…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2599

Published Apr 11, 2018

Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000153

Published Apr 5, 2018

A cross-site request forgery vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, De…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1,601-1,625 of 1,797 CVEsPage 65 of 72