← Back

Jenkins

jenkins

Vendor: Jenkins • 267 CVEs

CVEs (267)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Jenkins
Jun 17, 2026
Jul 26, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitabl...Show more
Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Jun 14, 2023
N/A· v4
8.0 HIGH· v3
N/A· v2
In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked...Show more
In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Mar 10, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise ina...Show more
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise inaccessible to attackers.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Mar 10, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a file parameter through the CLI, potenti...Show more
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a file parameter through the CLI, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Mar 10, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier shows temporary directories related to job workspaces, which allows attackers with Item/Workspace permission to access their contents.
1Jenkins
1Jenkins
Jun 17, 2026
Mar 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler....Show more
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Mar 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in hudson.util.Multipar...Show more
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in hudson.util.MultipartFormDataParser, allowing attackers to trigger a denial of service.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Mar 10, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially al...Show more
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used, potentially resulting in arbitrary code execution.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Mar 10, 2023
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the cur...Show more
Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide plugins to the configured update sites and have this message shown by Jenkins instances.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Sep 21, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploita...Show more
Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.Show less
4Debian
EclipseJenkins+1 more
8Debian Linux
Element Plug In For Vcenter ServerHci Compute Node+5 more
Jun 17, 2026
Jul 7, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can...Show more
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no enough resources left to process good requests.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Jun 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission chec...Show more
Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission checks in the corresponding view.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Jun 23, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username an...Show more
In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by at...Show more
In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.
1Jenkins
1Jenkins
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2...Show more
In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335) without further escaping, resulting in a cross-site scripting (XSS) vulnerability.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
4.3 MEDIUM· v2
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-19...Show more
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Feb 9, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.
5Debian
FedoraprojectJenkins+2 more
11Commerce Guided Search
Communications Brm Elastic Charging EngineCommunications Cloud Native Core Automated Test Suite+8 more
Jun 17, 2026
Feb 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel exe...Show more
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.Show less
2Jenkins
Oracle
2Communications Cloud Native Core Automated Test Suite
Jenkins
Jun 17, 2026
Jan 12, 2022
N/A· v4
4.3 MEDIUM· v3
2.6 LOW· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.