Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins jenkins vulnerabilities and exploits
(subscribe to this query)
8
CVSSv3
CVE-2017-1000086
The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups, restore backups, download backups, and also delete all previous backups via log rotation. Additionally, the plugin was not requiri...
Jenkins Periodic Backup 1.4
Jenkins Periodic Backup 1.3
Jenkins Periodic Backup 1.2
Jenkins Periodic Backup 1.1
Jenkins Periodic Backup 1.0
7.5
CVSSv3
CVE-2017-1000108
The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission instead.
Jenkins Pipeline-input-step 2.6
Jenkins Pipeline-input-step 2.5
Jenkins Pipeline-input-step 2.4
Jenkins Pipeline-input-step 2.3
Jenkins Pipeline-input-step 2.2
Jenkins Pipeline-input-step 2.1
Jenkins Pipeline-input-step 2.0
Jenkins Pipeline-input-step 2.7
8
CVSSv3
CVE-2023-35141
In Jenkins 2.399 and previous versions, LTS 2.387.3 and previous versions, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexp...
Jenkins Jenkins
8.8
CVSSv3
CVE-2020-2160
Jenkins 2.227 and previous versions, LTS 2.204.5 and previous versions uses different representations of request URL paths, which allows malicious users to craft URLs that allow bypassing CSRF protection of any target URL.
Jenkins Jenkins
7.5
CVSSv3
CVE-2017-1000394
Jenkins 2.73.1 and previous versions, 2.83 and previous versions bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenk...
Jenkins Jenkins
NA
CVE-2014-2058
BuildTrigger in Jenkins prior to 1.551 and LTS prior to 1.532.2 allows remote authenticated users to bypass access restrictions and execute arbitrary jobs by configuring a job to trigger another job. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7330.
Jenkins Jenkins
4.3
CVSSv3
CVE-2018-1999006
A exposure of sensitive information vulnerability exists in Jenkins 2.132 and previous versions, 2.121.1 and previous versions in Plugin.java that allows malicious users to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of t...
Jenkins Jenkins
7.5
CVSSv3
CVE-2018-1999043
A denial of service vulnerability exists in Jenkins 2.137 and previous versions, 2.121.2 and previous versions in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows malicious users to create ephemeral in-memory user records by attempting to log in u...
Jenkins Jenkins
5.4
CVSSv3
CVE-2018-1999045
A improper authentication vulnerability exists in Jenkins 2.137 and previous versions, 2.121.2 and previous versions in SecurityRealm.java, TokenBasedRememberMeServices2.java that allows attackers with a valid cookie to remain logged in even if that feature is disabled.
Jenkins Jenkins
4.3
CVSSv3
CVE-2018-1999046
A exposure of sensitive information vulnerability exists in Jenkins 2.137 and previous versions, 2.121.2 and previous versions in Computer.java that allows attackers With Overall/Read permission to access the connection log for any agent.
Jenkins Jenkins
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37884
CVE-2024-6003
remote
brute force
information disclosure
CVE-2024-27801
CVE-2024-30078
CVE-2024-31870
CVE-2024-6042
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »