jenkins Vulnerabilities and Affected Products
Vulnerabilities associated with cas.
Products
Clear product- jenkins11 vulnerabilities
- Jenkins Code Dx Plugin5 vulnerabilities
- cas2 vulnerabilities
- Script Security Plugin2 vulnerabilities
- script_security2 vulnerabilities
- blazemeter_plugin1 vulnerability
- docker1 vulnerability
- git_server1 vulnerability
- github1 vulnerability
- gitlab_hook1 vulnerability
- groovy1 vulnerability
- icescrum1 vulnerability
- Jenkins Command Line Interface (CLI)1 vulnerability
- Jenkins Stapler Web Framework1 vulnerability
- Jenkins User Interface (UI)1 vulnerability
- jenkins-mailer-plugin1 vulnerability
- jenkins-ssh-slaves-plugin1 vulnerability
- jenkins-telegram-bot1 vulnerability
- Matrix Project Plugin1 vulnerability
- mattermost1 vulnerability
- openid1 vulnerability
- openshift-sync-plugin1 vulnerability
- pipeline\1 vulnerability
- shared_library_version_override1 vulnerability
- subversion_partial_release_manager1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-4399CRITICAL | CAS <= 1.0.0 - Unauthenticated SSRFThe does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack | CVSS9.1v3.1 | EPSS1.82% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-4388HIGH | CAS <= 1.0.0 - Unauthenticated Arbitrary File AccessThis does not validate a path generated with user input when downloading files, allowing unauthenticated user to download arbitrary files from the server CWE-22May 23, 2024 | CVSS7.5v3.1 | EPSS0.719% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |