Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Git Parameter HIGH 8.2
CVE-2025-53652

Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the…

Fix: 444.vca_b_84d3703c2+
Fix from $1,950 2025-07-09
Credentials Binding HIGH 7.3
CVE-2025-53650

Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in except…

Fix: after 687.689.v1a_f775332fc
Fix from $1,950 2025-07-09
Statistics Gatherer MEDIUM 6.5
CVE-2025-53654

Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins controller…

Fix: after 2.0.3
Fix from $1,600 2025-07-09
Html Publisher MEDIUM 6.3
CVE-2025-53651

Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths of files archived during the Publish HTML reports…

Fix: 427+
Fix from $1,600 2025-07-09
Statistics Gatherer MEDIUM 5.3
CVE-2025-53655

Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for …

Fix: after 2.0.3
Fix from $1,600 2025-07-09
Jenkins MEDIUM 6.5
CVE-2024-9453

A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those l…

Mitigation only
Fix from $1,600 2025-07-04
Gatling HIGH 8.0
CVE-2025-5806

Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jen…

Fix: after 136.vb_9009b_3d33a_e
Fix from $1,950 2025-06-06
Wso2 Oauth CRITICAL 9.8
CVE-2025-47889

In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unau…

Fix: after 1.0
Fix from $2,300 2025-05-14
Openid Connect Provider CRITICAL 9.1
CVE-2025-47884

In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of enviro…

Fix: after 96.vee8ed882ec4d
Fix from $2,300 2025-05-14
Health Advisor By Cloudbees HIGH 8.8
CVE-2025-47885

Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting…

Fix: after 374.v194b_d4f0c8c8
Fix from $1,950 2025-05-14
Dingtalk MEDIUM 5.9
CVE-2025-47888

Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections to the configured Ding…

Fix: after 2.7.3
Fix from $1,600 2025-05-14
Ssh Agent CRITICAL 9.1
CVE-2025-32754

In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, causing all containe…

Fix: 6.11.2+
Fix from $2,300 2025-04-10
Ssh Slave CRITICAL 9.1
CVE-2025-32755

In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on Debian, causing all containers …

Mitigation only
Fix from $2,300 2025-04-10
Monitor Remote Job MEDIUM 5.5
CVE-2025-31725

Jenkins monitor-remote-job Plugin 1.0 stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by user…

Mitigation only
Fix from $1,600 2025-04-02
Stack Hammer MEDIUM 5.5
CVE-2025-31726

Jenkins Stack Hammer Plugin 1.0.6 and earlier stores Stack Hammer API keys unencrypted in job config.xml files on the Jenkins controller where they c…

Fix: after 1.0.6
Fix from $1,600 2025-04-02
Asakusasatellite MEDIUM 5.5
CVE-2025-31727

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controller wher…

Fix: after 0.1.1
Fix from $1,600 2025-04-02
Asakusasatellite MEDIUM 5.5
CVE-2025-31728

Jenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasing the pot…

Fix: after 0.1.1
Fix from $1,600 2025-04-02
Templating Engine HIGH 8.8
CVE-2025-31722

In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with It…

Fix: 2.5.4+
Fix from $1,950 2025-04-02
Anchorchain MEDIUM 6.5
CVE-2025-30196

Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the `javascript:` scheme, resulti…

Mitigation only
Fix from $1,600 2025-03-19
Jenkins MEDIUM 5.4
CVE-2025-27624

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their c…

Fix: 2.492.2 / 2.500+
Fix from $1,600 2025-03-05
Folder Based Authorization Strategy MEDIUM 6.8
CVE-2025-24401

Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabl…

Fix: after 217.vd5b_18537403e
Fix from $1,600 2025-01-22
Bitbucket Server Integration HIGH 8.8
CVE-2025-24398

Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection…

Fix: 4.1.4+
Fix from $1,950 2025-01-22
Openid Connect Authentication HIGH 8.8
CVE-2025-24399

Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive,…

Fix: 4.438.440.v3f5f201de5dc / 4.453.v4d7765c854f4+
Fix from $1,950 2025-01-22
Simple Queue HIGH 8.0
CVE-2024-54003EPSS 80%

Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitab…

Fix: after 1.4.4
Fix from $1,950 2024-11-27
Openid Connect Authentication HIGH 8.8
CVE-2024-52553

Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.

Fix: 4.421.v5422614eb_e0a+
Fix from $1,950 2024-11-13
Shared Library Version Override HIGH 8.8
CVE-2024-52554

Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not …

Fix: after 17.v786074c9fce7
Fix from $1,950 2024-11-13
Pipeline\ HIGH 8.0
CVE-2024-52550

Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script …

Fix: 3975.3977.v478dd9e956c3+
Fix from $1,950 2024-11-13
Pipeline\ HIGH 8.0
CVE-2024-52551

Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a bui…

Fix: after 2.2214.vb_b_34b_2ea_9b_83
Fix from $1,950 2024-11-13
Authorize Project HIGH 8.0
CVE-2024-52552

Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resulting in…

Fix: after 1.7.2
Fix from $1,950 2024-11-13
Openid Connect Authentication HIGH 8.1
CVE-2024-47806

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing atta…

Fix: 4.355.v3a_fb_fca_b_96d4+
Fix from $1,950 2024-10-02