← Back

Jenkins

jenkins

1,798 CVEs • 693 products

Products (693)

Click to collapse
Toggle
Jenkins
jenkins
Pipeline\
pipeline\
Git
git
Blue Ocean
blue_ocean
Subversion
subversion
Kubernetes
kubernetes
Rundeck
rundeck
Git Client
git_client
Github
github
Openid
openid
Gitlab
gitlab
Azure Ad
azure_ad
Electricflow
electricflow
Amazon Ec2
amazon_ec2
Git Parameter
git_parameter
Junit
junit
Mercurial
mercurial
Mailer
mailer
Google Login
google_login
Jira
jira
Job Import
job_import
Chef Sinatra
chef_sinatra
Mabl
mabl
Assembla
assembla
Delphix
delphix
Support Core
support_core
Fortify
fortify
Appspider
appspider
Scriptler
scriptler
Wso2 Oauth
wso2_oauth
Code Dx
code_dx
Ssh
ssh
Warnings
warnings
Maven
maven
Coverity
coverity
Ansible
ansible
S3 Publisher
s3_publisher
Credentials
credentials
Gogs
gogs
Icescrum
icescrum
Kubernetes Ci
kubernetes_ci
Team Concert
team_concert
Rapiddeploy
rapiddeploy
P4
p4
Requests
requests
Checkmarx
checkmarx
Proxmox
proxmox

CVEs (1,798)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Jenkins
Jun 17, 2026
Apr 2, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its conf...Show more
A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration.Show less
1Jenkins
1Zoho Qengine
Jun 17, 2026
Mar 19, 2025
N/A· v4
3.1 LOW· v3
N/A· v2
Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it.
1Jenkins
1Anchorchain
Jun 17, 2026
Mar 19, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by...Show more
Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control the input file for the Anchor Chain post-build step.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Mar 5, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a Jenkins URL that will...Show more
In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different site, because browsers interpret these characters as part of scheme-relative redirects.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Mar 5, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of sidepanel widgets (e.g., Build Queue and Bu...Show more
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of sidepanel widgets (e.g., Build Queue and Build Executor Status widgets).Show less
1Jenkins
1Jenkins
Jun 17, 2026
Mar 5, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via REST API or CLI, allowing attackers with View/Read permission to view encrypted valu...Show more
Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via REST API or CLI, allowing attackers with View/Read permission to view encrypted values of secrets.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Mar 5, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowing attackers with Agent/Extended Read permission to view enc...Show more
Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowing attackers with Agent/Extended Read permission to view encrypted values of secrets.Show less
1Jenkins
1Azure Service Fabric
Jun 17, 2026
Jan 22, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of Azure credentials stored in Jenkins.
1Jenkins
1Azure Service Fabric
Jun 17, 2026
Jan 22, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers to connect to a Service Fabric URL using attacker-specified credentials IDs obtained through anoth...Show more
A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers to connect to a Service Fabric URL using attacker-specified credentials IDs obtained through another method.Show less
1Jenkins
1Folder Based Authorization Strategy
Jun 17, 2026
Jan 22, 2025
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional per...Show more
Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.Show less
1Jenkins
1Eiffel Broadcaster
Jun 17, 2026
Jan 22, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate o...Show more
Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event published to RabbitMQ with the legitimate credentials.Show less
1Jenkins
1Openid Connect Authentication
Jun 17, 2026
Jan 22, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensiti...Show more
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in letter case, potentially gaining administrator access to Jenkins.Show less
1Jenkins
1Bitbucket Server Integration
Jun 17, 2026
Jan 22, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
1Jenkins
1Gitlab
Jun 17, 2026
Jan 22, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs...Show more
An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.Show less
1Jenkins
1Filesystem List Parameter
Jun 17, 2026
Nov 27, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jen...Show more
Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.Show less
1Jenkins
1Simple Queue
Jun 17, 2026
Nov 27, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Create permission.
1Jenkins
1Shared Library Version Override
Jun 17, 2026
Nov 13, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/C...Show more
Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to configure a folder-scoped library override that runs without sandbox protection.Show less
1Jenkins
1Openid Connect Authentication
Jun 17, 2026
Nov 13, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.
1Jenkins
1Authorize Project
Jun 17, 2026
Nov 13, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attac...Show more
Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Pipeline\
Jun 17, 2026
Nov 13, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Buil...Show more
Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved.Show less