CVEs (267)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as HTML when expanded, resulting in a stored XSS vulnerability exploitable by users with permission to d...Show more |
3Jenkins OracleRedhat3Communications Cloud Native Core Automated Test Suite JenkinsOpenshift Container PlatformJun 17, 2026 Aug 28, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for th...Show more |
3Jenkins OracleRedhat3Communications Cloud Native Core Automated Test Suite JenkinsOpenshift Container PlatformJun 17, 2026 Aug 28, 2019 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScr...Show more |
2Jenkins Redhat2Jenkins Openshift Container PlatformJun 17, 2026 Jul 17, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive infor...Show more |
CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection. |
A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter w...Show more |
3Jenkins OracleRedhat3Communications Cloud Native Core Automated Test Suite JenkinsOpenshift Container PlatformJun 17, 2026 Apr 10, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable...Show more |
3Jenkins OracleRedhat3Communications Cloud Native Core Automated Test Suite JenkinsOpenshift Container PlatformJun 17, 2026 Apr 10, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix...Show more |
A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/org/kohsuke/stapler/Facet.java, groovy/src/main/java/org/kohsuke/stapler...Show more |
2Jenkins Redhat2Jenkins Openshift Container PlatformJun 17, 2026 Jan 22, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration...Show more |
2Jenkins Redhat2Jenkins Openshift Container PlatformJun 17, 2026 Jan 22, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts...Show more |
An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/m...Show more |
A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing se...Show more |
A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission t...Show more |
A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbi...Show more |
A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permission to define a file...Show more |
2Jenkins Redhat2Jenkins Openshift Container PlatformNov 21, 2024 Dec 10, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop. |
2Jenkins Redhat2Jenkins Openshift Container PlatformNov 21, 2024 Dec 10, 2018 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user...Show more |
2Jenkins Redhat2Jenkins Openshift Container PlatformNov 21, 2024 Dec 10, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system...Show more |
2Jenkins Redhat2Jenkins Openshift Container PlatformNov 5, 2025 Dec 10, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invo...Show more |