jenkins
1,755 tracked vulnerabilities.
CVE-2024-28149
MEDIUM
Jenkins HTML Publisher Plugin 1.16-1.32 - Cross-Site Scripting via Improper Input Sanitization
Mar 06, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-23905
MEDIUM
Jenkins Red Hat Dependency Analytics Plugin < 0.7.1 - Stored Cross-Site Scripting via Disabled Content-Security-Policy
Jan 24, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-23904
HIGH
Jenkins Log Command Plugin < 1.0.2 - Unauthenticated Arbitrary File Read via Command Parser
Jan 24, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-23903
MEDIUM
Jenkins GitLab Branch Source Plugin <684 - Info Disclosure
Jan 24, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-23902
MEDIUM
Jenkins GitLab Branch Source Plugin < 684.vea_fa_7c1e2fe3 - Cross-Site Request Forgery
Jan 24, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-23901
MEDIUM
Jenkins GitLab Branch Source Plugin <684 - Info Disclosure
Jan 24, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-23900
MEDIUM
Jenkins Matrix Project Plugin <822.v01b_8c85d16d2 - Privilege Escal...
Jan 24, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-23899
MEDIUM
Jenkins Git Server Plugin < 99.va_0826a_b_cdfa_d - Arbitrary File Read via Command Parser
Jan 24, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-23898
HIGH
Jenkins 2.217-2.441 and LTS 2.222.1-2.426.2 - Cross-Site WebSocket Hijacking via CLI Endpoint
Jan 24, 2024
CVSS 8.8
EPSS 0.37
CVE-2024-23897
CRITICAL
KEVNUCLEI
Jenkins cli Ampersand Replacement Arbitrary File Read
Jan 24, 2024
CVSS 9.8
EPSS 0.94
CVE-2023-50779
MEDIUM
Jenkins PaaSLane Estimate Plugin < 1.0.4 - Missing Authorization
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50778
HIGH
Jenkins PaaSLane Estimate Plugin < 1.0.4 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-50777
MEDIUM
Jenkins PaaSLane Estimate Plugin <= 1.0.4 - Cleartext Storage of Sensitive Information
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50776
MEDIUM
Jenkins PaaSLane Estimate Plugin <= 1.0.4 - Cleartext Storage of Sensitive Information in Job config.xml
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50775
MEDIUM
Jenkins Deployment Dashboard Plugin < 1.0.10 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50774
HIGH
Jenkins HTMLResource Plugin 1.02 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-50773
MEDIUM
Jenkins Dingding JSON Pusher Plugin < 2.0 - Cleartext Storage of Sensitive Information
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50772
MEDIUM
Jenkins Dingding JSON Pusher Plugin <= 2.0 - Cleartext Storage of Sensitive Information in Job Config
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50771
MEDIUM
Jenkins OpenId Connect Authentication Plugin < 2.6 - Open Redirect via Login Redirect URL
Dec 13, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-50770
MEDIUM
Jenkins OpenId Connect Authentication Plugin < 2.6 - Insufficiently Protected Credentials
Dec 13, 2023
CVSS 6.7
EPSS 0.00
CVE-2023-50769
MEDIUM
Jenkins Nexus Platform Plugin < 3.18.0-03 - Missing Authorization
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50768
HIGH
Jenkins Nexus Platform Plugin < 3.18.0-03 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-50767
MEDIUM
Jenkins Nexus Platform Plugin < 3.18.0-03 - Server-Side Request Forgery via XML Response Parsing
Dec 13, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-50766
HIGH
Jenkins Nexus Platform Plugin < 3.18.0-03 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-50765
MEDIUM
Jenkins Scriptler Plugin < 342.v6a_89fd40f466 - Unauthorized Groovy Script Content Read via Script ID
Dec 13, 2023
CVSS 4.3
EPSS 0.00
Products
jenkins 259
pipeline\ 37
script_security 33
blue_ocean 11
git 11
email_extension 10
active_directory 9
build_failure_analyzer 9
config_file_provider 9
configuration_as_code 9
ns-nd_integration_performance_publisher 8
credentials_binding 7
github_branch_source 7
html_publisher 7
kubernetes 7
openid_connect_authentication 7
openshift_deployer 7
rundeck 7
subversion 7
amazon_ec2 6
azure_ad 6
azure_vm_agents 6
deployment_dashboard 6
electricflow 6
gerrit_trigger 6
github 6
github_pull_request_builder 6
gitlab 6
google_compute_engine 6
hashicorp_vault 6
Quick Filters