jenkins
1,755 tracked vulnerabilities.
CVE-2025-27624
MEDIUM
Jenkins < 2.492.2, 2.493-2.499 - Cross-Site Request Forgery
Mar 05, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-27623
MEDIUM
Jenkins < 2.492.2 and < 2.500 - Cleartext Storage of Sensitive Information in View Config
Mar 05, 2025
CVSS 4.3
EPSS 0.01
CVE-2025-27622
MEDIUM
Jenkins < 2.492.2, 2.493-2.499 - Cleartext Storage of Sensitive Information in Agent config.xml
Mar 05, 2025
CVSS 4.3
EPSS 0.01
CVE-2025-24403
MEDIUM
Jenkins Azure Service Fabric Plugin < 1.6 - Missing Authorization for Azure Credential ID Enumeration
Jan 22, 2025
CVSS 4.3
EPSS 0.01
CVE-2025-24402
MEDIUM
Jenkins Azure Service Fabric Plugin < 1.6 - Cross-Site Request Forgery
Jan 22, 2025
CVSS 4.3
EPSS 0.01
CVE-2025-24401
MEDIUM
Jenkins Folder-based Authorization Strategy Plugin < 217.vd5b_18537403e - Incorrect Authorization
Jan 22, 2025
CVSS 6.8
EPSS 0.00
CVE-2025-24400
MEDIUM
Jenkins Eiffel Broadcaster Plugin 2.8.0-2.10.2 - Incorrect Authorization via Credential ID Cache Key
Jan 22, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-24399
HIGH
Jenkins Openid Connect Authentication - Incorrect Default Permissions
Jan 22, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-24398
HIGH
Jenkins Bitbucket Server Integration Plugin 2.1.0-4.1.3 - Cross-Site Request Forgery Protection Bypass
Jan 22, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-24397
MEDIUM
Jenkins GitLab Plugin < 1.9.6 - Incorrect Authorization via Global Item/Configure Permission
Jan 22, 2025
CVSS 4.3
EPSS 0.01
CVE-2024-9453
MEDIUM
Jenkins - Sensitive Information Exposure via Unobfuscated Bearer Token in Logs
Jul 04, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-54004
MEDIUM
Jenkins Filesystem List Parameter Plugin <0.0.14 - Info Disclosure
Nov 27, 2024
CVSS 4.3
EPSS 0.01
CVE-2024-54003
HIGH
Jenkins Simple Queue Plugin <1.4.4 - XSS
Nov 27, 2024
CVSS 8.0
EPSS 0.41
CVE-2024-52554
HIGH
Jenkins Shared Library Version Override Plugin < 17.v786074c9fce7 - Missing Authorization
Nov 13, 2024
CVSS 8.8
EPSS 0.01
CVE-2024-52553
HIGH
Jenkins OpenId Connect Authentication Plugin < 4.421.v5422614eb_e0a - Insufficient Session Expiration
Nov 13, 2024
CVSS 8.8
EPSS 0.00
CVE-2024-52552
HIGH
Jenkins Authorize Project Plugin < 1.7.2 - Stored Cross-Site Scripting via Job Name Evaluation
Nov 13, 2024
CVSS 8.0
EPSS 0.04
CVE-2024-52551
HIGH
Jenkins Pipeline < 2.2214.vb_b_34b_2ea_9b_83 - Unapproved Script Execution via Build Restart
Nov 13, 2024
CVSS 8.0
EPSS 0.01
CVE-2024-52550
HIGH
Jenkins Pipeline: Groovy Plugin <3990.vd281dd77a_388 - Improper Input Validation
Nov 13, 2024
CVSS 8.0
EPSS 0.01
CVE-2024-52549
MEDIUM
Jenkins Script Security Plugin - Missing Authorization for File Existence Check
Nov 13, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-47807
HIGH
Jenkins OpenId Connect Authentication Plugin <4.354.321ce67a-1de8 -...
Oct 02, 2024
CVSS 8.1
EPSS 0.00
CVE-2024-47806
HIGH
Jenkins OpenId Connect Authentication Plugin <4.354.v321ce67a_1de8 ...
Oct 02, 2024
CVSS 8.1
EPSS 0.00
CVE-2024-47805
HIGH
Jenkins Credentials Plugin <1380.va - Info Disclosure
Oct 02, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-47804
MEDIUM
Jenkins < 2.462.3 and < 2.479 - Unauthenticated Item Creation Restriction Bypass via CLI or REST API
Oct 02, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-47803
MEDIUM
Jenkins < 2.462.3 and < 2.479 - Sensitive Information Exposure in Error Messages
Oct 02, 2024
CVSS 4.3
EPSS 0.01
CVE-2024-43045
MEDIUM
Jenkins <2.470-<2.452.3 - Info Disclosure
Aug 07, 2024
CVSS 6.3
EPSS 0.01
Products
jenkins 259
pipeline\ 37
script_security 33
blue_ocean 11
git 11
email_extension 10
active_directory 9
build_failure_analyzer 9
config_file_provider 9
configuration_as_code 9
ns-nd_integration_performance_publisher 8
credentials_binding 7
github_branch_source 7
html_publisher 7
kubernetes 7
openid_connect_authentication 7
openshift_deployer 7
rundeck 7
subversion 7
amazon_ec2 6
azure_ad 6
azure_vm_agents 6
deployment_dashboard 6
electricflow 6
gerrit_trigger 6
github 6
github_pull_request_builder 6
gitlab 6
google_compute_engine 6
hashicorp_vault 6
Quick Filters