Jenkins
jenkins
1,798 CVEs • 693 products
Products (693)
Click to collapseToggle
Products (693)
Click to collapse
CVEs (1,798)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks. |
It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks. |
jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Jul 23, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existenc...Show more |
A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Jul 23, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define J...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Jul 23, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress a...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Jul 23, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds. |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Jul 23, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning t...Show more |
2Jenkins Oracle2Communications Cloud Native Core Automated Test Suite JenkinsNov 21, 2024 Jul 23, 2018 N/A· v4 8.8 HIGH· v3 4.3 MEDIUM· v2 A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the c...Show more |
Jenkins project Jenkins AWS CodeBuild Plugin version 0.26 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSClientFactory.java, CodeBuilder.java that can result in Credentials Disclosure. Th...Show more |
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result in Credentials Disclosure. This attack a...Show more |
Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a File and Directory Information Exposure vulnerability in AWSCodeDeployPublisher.java that can result in Disclosure of environment variable...Show more |
Jenkins project Jenkins AWS CodePipeline Plugin version 0.36 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodePipelineSCM.java that can result in Credentials Disclosure. This attack app...Show more |
1Jenkins 1Configuration As Code Nov 21, 2024 Jun 26, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionConfigurator.java that...Show more |
1Jenkins 1Configuration As Code Nov 21, 2024 Jun 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overall/Read access to obtain the YAML export...Show more |
A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker with local file system access or control of a Jenkins administrator's...Show more |
1Jenkins 1Fortify Cloudscan Nov 21, 2024 Jun 26, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A arbitrary file write vulnerability exists in Jenkins Fortify CloudScan Plugin 1.5.1 and earlier in ArchiveUtil.java that allows attackers able to control rulepack zip file contents to overwrite any file on the Jenkins...Show more |
A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL...Show more |
A man in the middle vulnerability exists in Jenkins CollabNet Plugin 2.0.4 and earlier in CollabNetApp.java, CollabNetPlugin.java, CNFormFieldValidator.java that allows attackers to impersonate any service that Jenkins c...Show more |