Skip to main content

Vendor archive

jenkins CVEs

Beta · best-effort

1,797 CVEs tagged to vendor jenkins78 Critical, 476 High, 1,209 Medium, 34 Low, 0 Unrated.

CVE-2024-34146

Published May 2, 2024

Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing attackers with a previously con…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34145

Published May 2, 2024

A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34144

Published May 2, 2024

A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define an…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-2216

Published Mar 6, 2024

A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2215

Published Mar 6, 2024

A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL,…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28162

Published Mar 6, 2024

In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT)…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28161

Published Mar 6, 2024

In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled by def…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28160

Published Mar 6, 2024

Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by att…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28157

Published Mar 6, 2024

Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers a…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28156

Published Mar 6, 2024

Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scripting (XSS) vulnerability expl…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28155

Published Mar 6, 2024

Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to obtain information abo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28154

Published Mar 6, 2024

Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28153

Published Mar 6, 2024

Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored cross-site scripting (XSS) vuln…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28152

Published Mar 6, 2024

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in t…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28151

Published Mar 6, 2024

Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with Item/C…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28150

Published Mar 6, 2024

Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, resulting in a stored cross-site s…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28149

Published Mar 6, 2024

Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site script…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23905

Published Jan 24, 2024

Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artif…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23904

Published Jan 24, 2024

Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-23903

Published Jan 24, 2024

Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23902

Published Jan 24, 2024

A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier allows attackers to connect to an attacker-specified URL.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23901

Published Jan 24, 2024

Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to confi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23900

Published Jan 24, 2024

Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure perm…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 1,797 CVEsPage 8 of 72