jenkins

1,755 tracked vulnerabilities.

CVE-2021-21686 HIGH
Jenkins < 2.303.3 and < 2.319 - Path Traversal via Symbolic Link Following
Nov 04, 2021
CVSS 8.1
EPSS 0.01
CVE-2021-21685 CRITICAL
Jenkins < 2.303.3 and < 2.319 - Missing Authorization for Directory Creation via FilePath#mkdirs
Nov 04, 2021
CVSS 9.1
EPSS 0.00
CVE-2021-21684 MEDIUM
Jenkins Git Plugin < 4.8.2 - Stored Cross-Site Scripting via Git SHA-1 Checksum Parameter
Oct 06, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-21683 MEDIUM
Jenkins < 2.303.1, < 2.314 - Path Traversal via Windows File Browser
Oct 06, 2021
CVSS 6.5
EPSS 0.02
CVE-2021-21682 MEDIUM
Jenkins <2.314-<2.303.1 - Info Disclosure
Oct 06, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-21681 MEDIUM
Jenkins Nomad Plugin < 0.7.4 - Insufficiently Protected Docker Credentials
Aug 31, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-21680 HIGH
Jenkins Nested View Plugin < 1.20 - XML External Entity Injection
Aug 31, 2021
CVSS 7.1
EPSS 0.00
CVE-2021-21679 HIGH
Jenkins Azure AD Plugin < 179.vf6841393099e - Cross-Site Request Forgery Protection Bypass
Aug 31, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-21678 HIGH
Jenkins SAML Plugin < 2.0.7 - Cross-Site Request Forgery Protection Bypass
Aug 31, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-21677 HIGH
Jenkins Code Coverage API Plugin < 1.4.0 - Remote Code Execution via Untrusted Java Deserialization
Aug 31, 2021
CVSS 8.8
EPSS 0.01
CVE-2021-21676 MEDIUM
Jenkins requests-plugin < 2.2.7 - Missing Authorization in HTTP Endpoint
Jun 30, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-21675 MEDIUM
Jenkins requests-plugin < 2.2.12 - Cross-Site Request Forgery
Jun 30, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-21674 MEDIUM
Jenkins requests-plugin <2.2.6 - Info Disclosure
Jun 30, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-21673 MEDIUM
Jenkins CAS Plugin < 1.6.0 - Open Redirect via Legitimacy Bypass
Jun 30, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-21672 MEDIUM
Jenkins Selenium HTML Report Plugin <= 1.0 - XML External Entity Injection
Jun 30, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-21671 HIGH
Jenkins < 2.300, LTS < 2.289.2 - Session Fixation
Jun 30, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-21670 MEDIUM
Jenkins <2.299 - Privilege Escalation
Jun 30, 2021
CVSS 4.3
EPSS 0.01
CVE-2021-21669 CRITICAL
Jenkins Generic Webhook Trigger Plugin < 1.72 - XML External Entity Injection
Jun 18, 2021
CVSS 9.8
EPSS 0.00
CVE-2021-21668 MEDIUM
Jenkins Scriptler Plugin < 3.1 - Stored Cross-Site Scripting via Unescaped Script Content
Jun 16, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-21667 MEDIUM
Jenkins Scriptler Plugin < 3.2 - Stored Cross-Site Scripting in Job Configuration Forms
Jun 16, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-21666 MEDIUM
Jenkins Kiuwan Plugin < 1.6.0 - Reflected Cross-Site Scripting via Form Validation Endpoint
Jun 10, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-21665 HIGH
Jenkins XebiaLabs XL Deploy Plugin < 10.0.1 - Cross-Site Request Forgery
Jun 10, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-21664 MEDIUM
Jenkins XebiaLabs XL Deploy Plugin < 10.0.1 - Incorrect Authorization via URL Connection
Jun 10, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-21663 MEDIUM
Jenkins XebiaLabs XL Deploy Plugin <7.5.8 - Open Redirect
Jun 10, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-21662 MEDIUM
Jenkins XebiaLabs XL Deploy Plugin <10.0.1 - Info Disclosure
Jun 10, 2021
CVSS 4.3
EPSS 0.00