jenkins
1,755 tracked vulnerabilities.
CVE-2018-1000409
MEDIUM
Jenkins < 2.138.1, < 2.145 - Session Fixation via User Signup
Jan 09, 2019
CVSS 5.4
EPSS 0.00
CVE-2018-1000408
MEDIUM
Jenkins ACL Bypass and Metaprogramming RCE
Jan 09, 2019
CVSS 6.5
EPSS 0.00
CVE-2018-1000407
MEDIUM
Jenkins < 2.138.2 - Cross-Site Scripting via API URL Rendering
Jan 09, 2019
CVSS 6.1
EPSS 0.00
CVE-2018-1000406
MEDIUM
Jenkins < 2.138.1, < 2.145 - Authenticated Path Traversal and Arbitrary File Write via File Parameter
Jan 09, 2019
CVSS 6.5
EPSS 0.09
CVE-2018-1000866
HIGH
Pipeline: Groovy Plugin <2.59 - Code Injection
Dec 10, 2018
CVSS 8.8
EPSS 0.01
CVE-2018-1000865
HIGH
Jenkins Script Security Plugin < 1.47 - Sandbox Bypass via SandboxTransformer
Dec 10, 2018
CVSS 8.8
EPSS 0.01
CVE-2018-1000864
MEDIUM
Jenkins < 2.153 and LTS < 2.138.3 - Denial of Service via Infinite Loop in CronTab.java
Dec 10, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-1000863
HIGH
Jenkins <2.153 - Privilege Escalation
Dec 10, 2018
CVSS 8.2
EPSS 0.06
CVE-2018-1000862
MEDIUM
Jenkins < 2.138.4 - Information Exposure via DirectoryBrowserSupport
Dec 10, 2018
CVSS 4.3
EPSS 0.00
CVE-2018-1000861
CRITICAL
KEVNUCLEI
Jenkins < 2.138.3 and < 2.153 - Remote Code Execution via Stapler Framework URL Invocation
Dec 10, 2018
CVSS 9.8
EPSS 0.94
CVE-2018-1999047
MEDIUM
Jenkins <2.137-2.121.2 - Auth Bypass
Aug 23, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-1999046
MEDIUM
Jenkins <2.137-2.121.2 - Info Disclosure
Aug 23, 2018
CVSS 4.3
EPSS 0.00
CVE-2018-1999045
MEDIUM
Jenkins <2.137-2.121.2 - Auth Bypass
Aug 23, 2018
CVSS 5.4
EPSS 0.00
CVE-2018-1999044
MEDIUM
Jenkins < 2.138 - Denial of Service via Infinite Loop in CronTab.java
Aug 23, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-1999043
HIGH
Jenkins < 2.137 and < 2.121.2 - Denial of Service via Invalid Credential Login Attempts
Aug 23, 2018
CVSS 7.5
EPSS 0.00
CVE-2018-1999042
MEDIUM
Jenkins < 2.137 and < 2.121.2 - Deserialization of Untrusted Data via XStream2.java
Aug 23, 2018
CVSS 5.3
EPSS 0.00
CVE-2018-1999041
MEDIUM
Jenkins Tinfoil Security Plugin <1.6.1 - Info Disclosure
Aug 01, 2018
CVSS 5.5
EPSS 0.00
CVE-2018-1999040
HIGH
Jenkins Kubernetes Plugin <1.10.1 - Info Disclosure
Aug 01, 2018
CVSS 8.8
EPSS 0.00
CVE-2018-1999039
MEDIUM
Jenkins Confluence Publisher Plugin <2.0.1 - SSRF
Aug 01, 2018
CVSS 4.3
EPSS 0.00
CVE-2018-1999038
MEDIUM
Jenkins Publisher Over CIFS Plugin <0.10 - Confused Deputy
Aug 01, 2018
CVSS 4.2
EPSS 0.00
CVE-2018-1999037
MEDIUM
Jenkins Resource Disposer Plugin <0.11 - Info Disclosure
Aug 01, 2018
CVSS 4.3
EPSS 0.00
CVE-2018-1999036
MEDIUM
Jenkins SSH Agent Plugin <1.15 - Info Disclosure
Aug 01, 2018
CVSS 6.5
EPSS 0.00
CVE-2018-1999035
HIGH
Jenkins Inedo BuildMaster <1.3 - SSRF
Aug 01, 2018
CVSS 7.4
EPSS 0.00
CVE-2018-1999034
HIGH
Jenkins Inedo ProGet Plugin <0.8 - SSRF
Aug 01, 2018
CVSS 7.4
EPSS 0.00
CVE-2018-1999031
MEDIUM
Jenkins meliora-testlab Plugin <1.14 - Info Disclosure
Aug 01, 2018
CVSS 6.5
EPSS 0.00
Products
jenkins 259
pipeline\ 37
script_security 33
blue_ocean 11
git 11
email_extension 10
active_directory 9
build_failure_analyzer 9
config_file_provider 9
configuration_as_code 9
ns-nd_integration_performance_publisher 8
credentials_binding 7
github_branch_source 7
html_publisher 7
kubernetes 7
openid_connect_authentication 7
openshift_deployer 7
rundeck 7
subversion 7
amazon_ec2 6
azure_ad 6
azure_vm_agents 6
deployment_dashboard 6
electricflow 6
gerrit_trigger 6
github 6
github_pull_request_builder 6
gitlab 6
google_compute_engine 6
hashicorp_vault 6
Quick Filters