Skip to main content

Vendor archive

jenkins CVEs

Beta · best-effort

1,797 CVEs tagged to vendor jenkins78 Critical, 476 High, 1,209 Medium, 34 Low, 0 Unrated.

CVE-2025-64140

Published Oct 29, 2025

Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64139

Published Oct 29, 2025

A missing permission check in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64138

Published Oct 29, 2025

A cross-site request forgery (CSRF) vulnerability in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64137

Published Oct 29, 2025

A missing permission check in Jenkins Themis Plugin 1.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64136

Published Oct 29, 2025

A cross-site request forgery (CSRF) vulnerability in Jenkins Themis Plugin 1.4.1 and earlier allows attackers to connect to an attacker-specified HTTP server.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64135

Published Oct 29, 2025

Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value, disabling a protecti…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64134

Published Oct 29, 2025

Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64133

Published Oct 29, 2025

A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and earlier allows attackers to execute sandboxed Groovy code.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64132

Published Oct 29, 2025

Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information abo…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64131

Published Oct 29, 2025

Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-59476

Published Sep 17, 2025

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attacke…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59475

Published Sep 17, 2025

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read pe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59474

Published Sep 17, 2025

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58460

Published Sep 3, 2025

A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b_92b_cd64 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58459

Published Sep 3, 2025

Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to e…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58458

Published Sep 3, 2025

In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the contr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53743

Published Jul 9, 2025

Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential for attackers to observe and…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53742

Published Jul 9, 2025

Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53678

Published Jul 9, 2025

Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53677

Published Jul 9, 2025

Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attackers to observe and capture it.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53676

Published Jul 9, 2025

Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53675

Published Jul 9, 2025

Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extend…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53674

Published Jul 9, 2025

Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing the potential for attackers to…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53673

Published Jul 9, 2025

Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the Jenkins controller, where it c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53672

Published Jul 9, 2025

Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users wit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 1,797 CVEsPage 4 of 72