Skip to main content

Vendor archive

jenkins CVEs

Beta · best-effort

1,797 CVEs tagged to vendor jenkins78 Critical, 476 High, 1,209 Medium, 34 Low, 0 Unrated.

CVE-2017-1000107

Published Oct 5, 2017

Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000106

Published Oct 5, 2017

Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corr…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000105

Published Oct 5, 2017

The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Ite…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000104

Published Oct 5, 2017

The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000103

Published Oct 5, 2017

The custom Details view of the Static Analysis Utilities based DRY Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000102

Published Oct 5, 2017

The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000096

Published Oct 5, 2017

Arbitrary code execution due to incomplete sandbox protection: Constructors, instance variable initializers, and instance initializers in Pipeline scripts were not subject to sand…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000095

Published Oct 5, 2017

The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, String). These allowed circumve…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000094

Published Oct 5, 2017

Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use to authenticate with a Docker Registry. Th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000093

Published Oct 5, 2017

Poll SCM Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to initiate polling of…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000092

Published Oct 5, 2017

Git Plugin connects to a user-specified Git repository as part of form validation. An attacker with no direct access to Jenkins but able to guess at a username/password credential…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000091

Published Oct 5, 2017

GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan Credentials are cor…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000089

Published Oct 5, 2017

Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000088

Published Oct 5, 2017

The Sidebar Link plugin allows users able to configure jobs, views, and agents to add entries to the sidebar of these objects. There was no input validation, which meant users wer…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000087

Published Oct 5, 2017

GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permissio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000086

Published Oct 5, 2017

The Periodic Backup Plugin did not perform any permission checks, allowing any user with Overall/Read access to change its settings, trigger backups, restore backups, download bac…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1000085

Published Oct 5, 2017

Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality improperly checked permission…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000084

Published Oct 5, 2017

Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9635

Published Sep 12, 2017

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to ob…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9634

Published Sep 12, 2017

Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercept…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000362

Published Jul 17, 2017

The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup directory with all old secrets, and…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4988

Published Feb 9, 2017

Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspec…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4987

Published Feb 9, 2017

Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4986

Published Feb 9, 2017

Directory traversal vulnerability in the TAP plugin before 1.25 in Jenkins allows remote attackers to read arbitrary files via an unspecified parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,701-1,725 of 1,797 CVEsPage 69 of 72