jenkins Vulnerabilities and Affected Products
Vulnerabilities associated with jenkins.
Products
Clear product- jenkins11 vulnerabilities
- Jenkins Code Dx Plugin5 vulnerabilities
- cas2 vulnerabilities
- Script Security Plugin2 vulnerabilities
- script_security2 vulnerabilities
- blazemeter_plugin1 vulnerability
- docker1 vulnerability
- git_server1 vulnerability
- github1 vulnerability
- gitlab_hook1 vulnerability
- groovy1 vulnerability
- icescrum1 vulnerability
- Jenkins Command Line Interface (CLI)1 vulnerability
- Jenkins Stapler Web Framework1 vulnerability
- Jenkins User Interface (UI)1 vulnerability
- jenkins-mailer-plugin1 vulnerability
- jenkins-ssh-slaves-plugin1 vulnerability
- jenkins-telegram-bot1 vulnerability
- Matrix Project Plugin1 vulnerability
- mattermost1 vulnerability
- openid1 vulnerability
- openshift-sync-plugin1 vulnerability
- pipeline\1 vulnerability
- shared_library_version_override1 vulnerability
- subversion_partial_release_manager1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-53435HIGH | Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonationIn Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller. CWE-502Jun 10, 2026 | CVSS8.8v3.1 | EPSS19% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59474MEDIUM | Jenkins has a missing permission check, allowing users to obtain agent namesJenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget. | CVSS5.3v3.1 | EPSS4.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-34148MEDIUM | Jenkins Subversion Partial Release Manager Plugin programmatically disables the fix for CVE-2016-3721Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefinedParameters'. CWE-1321May 2, 2024 | CVSS6.8v3.1 | EPSS0.787% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Arbitrary file read vulnerability through the Jenkins CLI can lead to RCEJenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system. | CVSS-v4.0 | EPSS>99.9% | PoCs48 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX | |
CVE-2023-43497HIGH | Jenkins temporary uploaded file created with insecure permissionsIn Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used. CWE-434Sep 20, 2023 | CVSS8.1v3.1 | EPSS0.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2012-4441MEDIUM | Jenkins CI Game Plugin allows Cross-Site Scripting (XSS)Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin. CWE-79Nov 18, 2019 | CVSS6.1v3.1 | EPSS1.87% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2012-4440MEDIUM | Jenkins Violation Plugin allows Cross-Site Scripting (XSS)Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin. CWE-79Nov 18, 2019 | CVSS6.1v3.1 | EPSS1.87% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2012-4439MEDIUM | Jenkins allows Cross-Site Scripting (XSS) via Crafted URLCross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins. CWE-79Nov 18, 2019 | CVSS6.1v3.1 | EPSS1.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2012-4438HIGH | Jenkins allows Data Insertion and Execution of Code by those with Read and HTTP AccessJenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code. CWE-20Nov 18, 2019 | CVSS8.8v3.1 | EPSS2.39% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-1000353CRITICAL | Deserialization of Untrusted Data in JenkinsJenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI… | CVSS9.8v3.1 | EPSS99.7% | PoCs4 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2016-9299CRITICAL | Improper Neutralization of Special Elements used in an LDAP Query in JenkinsThe remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server. | CVSS9.8v3.0 | EPSS96.9% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |