← Back

Jenkins

jenkins

1,798 CVEs • 693 products

Products (693)

Click to collapse
Toggle
Jenkins
jenkins
Pipeline\
pipeline\
Git
git
Blue Ocean
blue_ocean
Subversion
subversion
Kubernetes
kubernetes
Rundeck
rundeck
Git Client
git_client
Github
github
Openid
openid
Gitlab
gitlab
Azure Ad
azure_ad
Electricflow
electricflow
Amazon Ec2
amazon_ec2
Git Parameter
git_parameter
Junit
junit
Mercurial
mercurial
Mailer
mailer
Google Login
google_login
Jira
jira
Job Import
job_import
Chef Sinatra
chef_sinatra
Mabl
mabl
Assembla
assembla
Delphix
delphix
Support Core
support_core
Fortify
fortify
Appspider
appspider
Scriptler
scriptler
Wso2 Oauth
wso2_oauth
Code Dx
code_dx
Ssh
ssh
Warnings
warnings
Maven
maven
Coverity
coverity
Ansible
ansible
S3 Publisher
s3_publisher
Credentials
credentials
Gogs
gogs
Icescrum
icescrum
Kubernetes Ci
kubernetes_ci
Team Concert
team_concert
Rapiddeploy
rapiddeploy
P4
p4
Requests
requests
Checkmarx
checkmarx
Proxmox
proxmox

CVEs (1,798)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
4Google Compute Engine
JiraMatlab+1 more
Jun 17, 2026
Nov 29, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified usernam...Show more
A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.Show less
1Jenkins
1Matlab
Jun 17, 2026
Nov 29, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
1Jenkins
1Matlab
Jun 17, 2026
Nov 29, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11.0 and earlier allows attackers to have Jenkins parse an XML file from the Jenkins controller file system.
1Jenkins
1Matlab
Jun 17, 2026
Nov 29, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system.
1Jenkins
1Jira
Jun 17, 2026
Nov 29, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
1Jenkins
1Google Compute Engine
Jun 17, 2026
Nov 29, 2023
N/A· v4
2.7 LOW· v3
N/A· v2
Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job)...Show more
Incorrect permission checks in Jenkins Google Compute Engine Plugin 4.550.vb_327fca_3db_11 and earlier allow attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate system-scoped credentials IDs of credentials stored in Jenkins and to connect to Google Cloud Platform using attacker-specified credentials IDs obtained through another method, to obtain information about existing projects. This fix has been backported to 4.3.17.1.Show less
1Jenkins
1Zanata
Jun 17, 2026
Oct 25, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Jenkins Zanata Plugin 0.6 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token hashes are equal, potentially allowing attackers to use statistical methods...Show more
Jenkins Zanata Plugin 0.6 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token hashes are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.Show less
1Jenkins
1Edgewall Trac
Jun 17, 2026
Oct 25, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins Edgewall Trac Plugin 1.13 and earlier does not escape the Trac website URL on the build page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission...Show more
Jenkins Edgewall Trac Plugin 1.13 and earlier does not escape the Trac website URL on the build page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Msteams Webhook Trigger
Jun 17, 2026
Oct 25, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statist...Show more
Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.Show less
1Jenkins
1Gogs
Jun 17, 2026
Oct 25, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to ob...Show more
Jenkins Gogs Plugin 1.0.15 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.Show less
1Jenkins
1Multibranch Scan Webhook Trigger
Jun 17, 2026
Oct 25, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Jenkins Multibranch Scan Webhook Trigger Plugin 1.0.9 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to us...Show more
Jenkins Multibranch Scan Webhook Trigger Plugin 1.0.9 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.Show less
1Jenkins
1Cloudbees Cd
Jun 17, 2026
Oct 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which artifacts are published during the 'CloudBees CD - Publish Artifact' post-build step, allowing attack...Show more
Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which artifacts are published during the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to publish arbitrary files from the Jenkins controller file system to the previously configured CloudBees CD server.Show less
1Jenkins
1Cloudbees Cd
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers...Show more
Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to delete arbitrary files on the Jenkins controller file system.Show less
1Jenkins
1Lambdatest Automation
Jun 17, 2026
Oct 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, potentially resulting in its exposure.
1Jenkins
1Lambdatest Automation
Jun 17, 2026
Oct 25, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins lambdatest-automation Plugin 1.20.9 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of LAMBDATEST credentials stored in Jenkins.
1Jenkins
1Warnings
Jun 17, 2026
Oct 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. This f...Show more
Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. This fix has been backported to 10.4.1.Show less
1Jenkins
1Github
Jun 17, 2026
Oct 25, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins GitHub Plugin 1.37.3 and earlier does not escape the GitHub project URL on the build page when showing changes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Co...Show more
Jenkins GitHub Plugin 1.37.3 and earlier does not escape the GitHub project URL on the build page when showing changes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
3Debian
EclipseJenkins
3Debian Linux
JenkinsJetty
Jun 17, 2026
Oct 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an integer overflow in `MetaDataBuilder.checkSize` allows for HTTP/2 HPACK...Show more
Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an integer overflow in `MetaDataBuilder.checkSize` allows for HTTP/2 HPACK header values to exceed their size limit. `MetaDataBuilder.java` determines if a header name or value exceeds the size limit, and throws an exception if the limit is exceeded. However, when length is very large and huffman is true, the multiplication by 4 in line 295 will overflow, and length will become negative. `(_size+length)` will now be negative, and the check on line 296 will not be triggered. Furthermore, `MetaDataBuilder.checkSize` allows for user-entered HPACK header value sizes to be negative, potentially leading to a very large buffer allocation later on when the user-entered size is multiplied by 2. This means that if a user provides a negative length value (or, more precisely, a length value which, when multiplied by the 4/3 fudge factor, is negative), and this length value is a very large positive number when multiplied by 2, then the user can cause a very large buffer to be allocated on the server. Users of HTTP/2 can be impacted by a remote denial of service attack. The issue has been fixed in versions 11.0.16, 10.0.16, and 9.4.53. There are no known workarounds.Show less
33Akka
AmazonApache+30 more
165.net
3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 more
Jun 17, 2026
Oct 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
1Jenkins
1Build Failure Analyzer
Jun 17, 2026
Sep 20, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to delete Failure Causes.