jenkins

1,755 tracked vulnerabilities.

CVE-2024-28149 MEDIUM
Jenkins HTML Publisher Plugin 1.16-1.32 - Cross-Site Scripting via Improper Input Sanitization
Mar 06, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-23905 MEDIUM
Jenkins Red Hat Dependency Analytics Plugin < 0.7.1 - Stored Cross-Site Scripting via Disabled Content-Security-Policy
Jan 24, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-23904 HIGH
Jenkins Log Command Plugin < 1.0.2 - Unauthenticated Arbitrary File Read via Command Parser
Jan 24, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-23903 MEDIUM
Jenkins GitLab Branch Source Plugin <684 - Info Disclosure
Jan 24, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-23902 MEDIUM
Jenkins GitLab Branch Source Plugin < 684.vea_fa_7c1e2fe3 - Cross-Site Request Forgery
Jan 24, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-23901 MEDIUM
Jenkins GitLab Branch Source Plugin <684 - Info Disclosure
Jan 24, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-23900 MEDIUM
Jenkins Matrix Project Plugin <822.v01b_8c85d16d2 - Privilege Escal...
Jan 24, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-23899 MEDIUM
Jenkins Git Server Plugin < 99.va_0826a_b_cdfa_d - Arbitrary File Read via Command Parser
Jan 24, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-23898 HIGH
Jenkins 2.217-2.441 and LTS 2.222.1-2.426.2 - Cross-Site WebSocket Hijacking via CLI Endpoint
Jan 24, 2024
CVSS 8.8
EPSS 0.37
CVE-2024-23897 CRITICAL KEVNUCLEI
Jenkins cli Ampersand Replacement Arbitrary File Read
Jan 24, 2024
CVSS 9.8
EPSS 0.94
CVE-2023-50779 MEDIUM
Jenkins PaaSLane Estimate Plugin < 1.0.4 - Missing Authorization
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50778 HIGH
Jenkins PaaSLane Estimate Plugin < 1.0.4 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-50777 MEDIUM
Jenkins PaaSLane Estimate Plugin <= 1.0.4 - Cleartext Storage of Sensitive Information
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50776 MEDIUM
Jenkins PaaSLane Estimate Plugin <= 1.0.4 - Cleartext Storage of Sensitive Information in Job config.xml
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50775 MEDIUM
Jenkins Deployment Dashboard Plugin < 1.0.10 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50774 HIGH
Jenkins HTMLResource Plugin 1.02 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-50773 MEDIUM
Jenkins Dingding JSON Pusher Plugin < 2.0 - Cleartext Storage of Sensitive Information
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50772 MEDIUM
Jenkins Dingding JSON Pusher Plugin <= 2.0 - Cleartext Storage of Sensitive Information in Job Config
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50771 MEDIUM
Jenkins OpenId Connect Authentication Plugin < 2.6 - Open Redirect via Login Redirect URL
Dec 13, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-50770 MEDIUM
Jenkins OpenId Connect Authentication Plugin < 2.6 - Insufficiently Protected Credentials
Dec 13, 2023
CVSS 6.7
EPSS 0.00
CVE-2023-50769 MEDIUM
Jenkins Nexus Platform Plugin < 3.18.0-03 - Missing Authorization
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50768 HIGH
Jenkins Nexus Platform Plugin < 3.18.0-03 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-50767 MEDIUM
Jenkins Nexus Platform Plugin < 3.18.0-03 - Server-Side Request Forgery via XML Response Parsing
Dec 13, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-50766 HIGH
Jenkins Nexus Platform Plugin < 3.18.0-03 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-50765 MEDIUM
Jenkins Scriptler Plugin < 342.v6a_89fd40f466 - Unauthorized Groovy Script Content Read via Script ID
Dec 13, 2023
CVSS 4.3
EPSS 0.00