← Back

Jenkins

jenkins

1,798 CVEs • 693 products

Products (693)

Click to collapse
Toggle
Jenkins
jenkins
Pipeline\
pipeline\
Git
git
Blue Ocean
blue_ocean
Subversion
subversion
Kubernetes
kubernetes
Rundeck
rundeck
Git Client
git_client
Github
github
Openid
openid
Gitlab
gitlab
Azure Ad
azure_ad
Electricflow
electricflow
Amazon Ec2
amazon_ec2
Git Parameter
git_parameter
Junit
junit
Mercurial
mercurial
Mailer
mailer
Google Login
google_login
Jira
jira
Job Import
job_import
Chef Sinatra
chef_sinatra
Mabl
mabl
Assembla
assembla
Delphix
delphix
Support Core
support_core
Fortify
fortify
Appspider
appspider
Scriptler
scriptler
Wso2 Oauth
wso2_oauth
Code Dx
code_dx
Ssh
ssh
Warnings
warnings
Maven
maven
Coverity
coverity
Ansible
ansible
S3 Publisher
s3_publisher
Credentials
credentials
Gogs
gogs
Icescrum
icescrum
Kubernetes Ci
kubernetes_ci
Team Concert
team_concert
Rapiddeploy
rapiddeploy
P4
p4
Requests
requests
Checkmarx
checkmarx
Proxmox
proxmox

CVEs (1,798)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Build Failure Analyzer
Jun 17, 2026
Sep 20, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username...Show more
A missing permission check in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified hostname and port using attacker-specified username and password.Show less
1Jenkins
1Build Failure Analyzer
Jun 17, 2026
Sep 20, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and pa...Show more
A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.Show less
1Jenkins
1Build Failure Analyzer
Jun 17, 2026
Sep 20, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or update...Show more
Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or update Failure Causes.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Sep 20, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the default system temporary directory with the default permissions for newly create...Show more
In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Sep 20, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default system temporary directory with the default permissions for newly crea...Show more
In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Sep 20, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly created files when installing a plugin from a URL, potentially allowing...Show more
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly created files when installing a plugin from a URL, potentially allowing attackers with access to the system temporary directory to replace the file before it is installed in Jenkins, potentially resulting in arbitrary code execution.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Sep 20, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of 'ExpandableDetailsNote', resulting in a stored cross-site scripting (XSS) vulnerability exploitable b...Show more
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of 'ExpandableDetailsNote', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control this parameter.Show less
1Jenkins
1Jenkins
Jun 17, 2026
Sep 20, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing...Show more
Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.Show less
1Jenkins
1Frugal Testing
Jun 17, 2026
Sep 6, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to Frugal Testing using attacker-specified credentials.
1Jenkins
1Frugal Testing
Jun 17, 2026
Sep 6, 2023
N/A· v4
3.5 LOW· v3
N/A· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to connect to Frugal Testing using attacker-specified credentials, and to retrieve test IDs and names fr...Show more
A cross-site request forgery (CSRF) vulnerability in Jenkins Frugal Testing Plugin 1.1 and earlier allows attackers to connect to Frugal Testing using attacker-specified credentials, and to retrieve test IDs and names from Frugal Testing, if a valid credential corresponds to the attacker-specified username.Show less
1Jenkins
1Assembla Auth
Jun 17, 2026
Sep 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if...Show more
Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted.Show less
1Jenkins
1Aws Codecommit Trigger
Jun 17, 2026
Sep 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not escape the queue name parameter passed to a form validation URL, when rendering an error message, resulting in an HTML injection vulnerability.
1Jenkins
1Aws Codecommit Trigger
Jun 17, 2026
Sep 6, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to clear the SQS queue.
1Jenkins
1Aws Codecommit Trigger
Jun 17, 2026
Sep 6, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers to clear the SQS queue.
1Jenkins
1Aws Codecommit Trigger
Jun 17, 2026
Sep 6, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A missing permission check in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins.
1Jenkins
1Tap
Jun 17, 2026
Sep 6, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jenkins TAP Plugin 2.3 and earlier does not escape TAP file contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control TAP file contents.
1Jenkins
1Ssh2 Easy
Jun 17, 2026
Sep 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access...Show more
Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.Show less
1Jenkins
1Ivy
Jun 17, 2026
Sep 6, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A cross-site request forgery (CSRF) vulnerability in Jenkins Ivy Plugin 2.5 and earlier allows attackers to delete disabled modules.
1Jenkins
1Bitbucket Push And Pull Request
Jun 17, 2026
Sep 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URL...Show more
Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.Show less
1Jenkins
1Google Login
Jun 17, 2026
Sep 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtai...Show more
Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtain a valid token.Show less