Showing 11 vulnerabilities on this page for jenkins

Signals CISA KEV Ransomware Nuclei
jenkins vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.

CWE-502Jun 10, 2026
CVSS8.8v3.1EPSS19%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Jenkins has a missing permission check, allowing users to obtain agent names

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget.

CWE-862Sep 17, 20251 related artifact
CVSS5.3v3.1EPSS4.74%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Jenkins Subversion Partial Release Manager Plugin programmatically disables the fix for CVE-2016-3721

Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefinedParameters'.

CWE-1321May 2, 2024
CVSS6.8v3.1EPSS0.787%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.

CWE-22CWE-27Jan 24, 20241 related artifact
CVSS-v4.0EPSS>99.9%PoCs48SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Jenkins temporary uploaded file created with insecure permissions

In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.

CWE-434Sep 20, 2023
CVSS8.1v3.1EPSS0.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Jenkins CI Game Plugin allows Cross-Site Scripting (XSS)

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.

CWE-79Nov 18, 2019
CVSS6.1v3.1EPSS1.87%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Jenkins Violation Plugin allows Cross-Site Scripting (XSS)

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.

CWE-79Nov 18, 2019
CVSS6.1v3.1EPSS1.87%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Jenkins allows Cross-Site Scripting (XSS) via Crafted URL

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

CWE-79Nov 18, 2019
CVSS6.1v3.1EPSS1.85%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Jenkins allows Data Insertion and Execution of Code by those with Read and HTTP Access

Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.

CWE-20Nov 18, 2019
CVSS8.8v3.1EPSS2.39%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Deserialization of Untrusted Data in Jenkins

Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI

CWE-502Jan 29, 20181 related artifact
CVSS9.8v3.1EPSS99.7%PoCs4SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Improper Neutralization of Special Elements used in an LDAP Query in Jenkins

The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.

CWE-90Jan 12, 20171 related artifact
CVSS9.8v3.0EPSS96.9%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX