Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Batch Task MEDIUM 5.4
CVE-2022-23115

Cross-site request forgery (CSRF) vulnerabilities in Jenkins batch task Plugin 1.19 and earlier allows attackers with Overall/Read access to retrieve…

Fix: after 1.19
Fix from $1,600 2022-01-12
Configuration As Code MEDIUM 5.3
CVE-2022-23106

Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing a…

Fix: after 1.55
Fix from $1,600 2022-01-12
Docker Commons HIGH 8.8
CVE-2022-20617

Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability ex…

Fix: after 1.17
Fix from $1,950 2022-01-12
Matrix Project MEDIUM 5.4
CVE-2022-20615EPSS 82%

Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a st…

Fix: after 1.19
Fix from $1,600 2022-01-12
Squash Tm Publisher HIGH 8.1
CVE-2021-43578

Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier implements an agent-to-controller message that does not implement any validatio…

Fix: after 1.0.0
Fix from $1,950 2021-11-12
Owasp Dependency Check HIGH 7.1
CVE-2021-43577

Jenkins OWASP Dependency-Check Plugin 5.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 5.1.1
Fix from $1,950 2021-11-12
Performance MEDIUM 6.5
CVE-2021-21701

Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 3.20
Fix from $1,600 2021-11-12
Pom2config MEDIUM 6.5
CVE-2021-43576

Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Ove…

Fix: after 1.2
Fix from $1,600 2021-11-12
Active Choices MEDIUM 5.4
CVE-2021-21699EPSS 88%

Jenkins Active Choices Plugin 2.5.6 and earlier does not escape the parameter name of reactive parameters and dynamic reference parameters, resulting…

Fix: after 2.5.6
Fix from $1,600 2021-11-12
Scriptler MEDIUM 5.4
CVE-2021-21700

Jenkins Scriptler Plugin 3.3 and earlier does not escape the name of scripts on the UI when asking to confirm their deletion, resulting in a stored c…

Fix: after 3.3
Fix from $1,600 2021-11-12
Jenkins CRITICAL 9.8
CVE-2021-21690

Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, …

Fix: 2.303.3 / 2.319+
Fix from $2,300 2021-11-04
Jenkins CRITICAL 9.8
CVE-2021-21691

Creating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318 and earlier, LTS 2.303.2 and…

Fix: 2.303.3 / 2.319+
Fix from $2,300 2021-11-04
Jenkins CRITICAL 9.8
CVE-2021-21692

FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier only check 'read' agent-to-controller access p…

Fix: 2.303.3 / 2.319+
Fix from $2,300 2021-11-04
Jenkins CRITICAL 9.8
CVE-2021-21693

When creating temporary files, agent-to-controller access to create those files is only checked after they've been created in Jenkins 2.318 and earli…

Fix: 2.303.3 / 2.319+
Fix from $2,300 2021-11-04
Jenkins CRITICAL 9.8
CVE-2021-21694

FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check any permissions in Jenkins 2…

Fix: 2.303.3 / 2.319+
Fix from $2,300 2021-11-04
Jenkins CRITICAL 9.8
CVE-2021-21696

Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not limit agent read/write access to the libs/ directory inside build directories when using …

Fix: after 2.318
Fix from $2,300 2021-11-04
Jenkins CRITICAL 9.1
CVE-2021-21687

Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic lin…

Fix: 2.303.3 / 2.319+
Fix from $2,300 2021-11-04
Jenkins CRITICAL 9.1
CVE-2021-21689

FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access control in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.

Fix: 2.303.3 / 2.319+
Fix from $2,300 2021-11-04
Jenkins CRITICAL 9.1
CVE-2021-21697

Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to read and write the contents of any build directory stored in Jenkins with very…

Fix: after 2.318
Fix from $2,300 2021-11-04
Jenkins HIGH 8.8
CVE-2021-21695

FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Jenkins 2.318 and earlier, LTS …

Fix: 2.303.3 / 2.319+
Fix from $1,950 2021-11-04
Jenkins HIGH 8.1
CVE-2021-21686

File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allo…

Fix: 2.303.3 / 2.319+
Fix from $1,950 2021-11-04
Jenkins HIGH 7.5
CVE-2021-21688

The agent-to-controller security check FilePath#reading(FileVisitor) in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not reject any operat…

Fix: 2.303.3 / 2.319+
Fix from $1,950 2021-11-04
Subversion HIGH 7.5
CVE-2021-21698

Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an age…

Fix: after 2.15.0
Fix from $1,950 2021-11-04
Jenkins CRITICAL 9.1
CVE-2021-21685

Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create parent directories in FilePath#mkdirs.

Fix: 2.303.3 / 2.319+
Fix from $2,300 2021-11-04
Jenkins MEDIUM 6.5
CVE-2021-21683

The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows, resulting in a path …

Fix: after 2.314
Fix from $1,600 2021-10-06
Git MEDIUM 6.1
CVE-2021-21684

Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a bui…

Fix: after 4.8.2
Fix from $1,600 2021-10-06
Code Coverage Api HIGH 8.8
CVE-2021-21677

Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java objects it deserializes from dis…

Fix: after 1.4.0
Fix from $1,950 2021-08-31
Saml HIGH 8.8
CVE-2021-21678

Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.

Fix: after 2.0.7
Fix from $1,950 2021-08-31
Azure Ad HIGH 8.8
CVE-2021-21679

Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenki…

Fix: after 179.vf6841393099e
Fix from $1,950 2021-08-31
Nested View HIGH 7.1
CVE-2021-21680

Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) attacks.

Fix: after 1.20
Fix from $1,950 2021-08-31