Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openid Connect Authentication HIGH 8.1
CVE-2024-47807

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attack…

Fix: 4.355.v3a_fb_fca_b_96d4+
Fix from $1,950 2024-10-02
Credentials HIGH 7.5
CVE-2024-47805

Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using…

Fix: 1371.1373.v4eb_fa_b_7161e9 / 1380.va_435002fa_924+
Fix from $1,950 2024-10-02
Jenkins HIGH 8.8
CVE-2024-43044EPSS 29%

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using th…

Fix: 2.452.4 / 2.471+
Fix from $1,950 2024-08-07
Jenkins MEDIUM 6.3
CVE-2024-43045

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read perm…

Fix: 2.452.4 / 2.471+
Fix from $1,600 2024-08-07
Script Security CRITICAL 9.8
CVE-2024-34144EPSS 48%

A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attacker…

Fix: after 1335.vf07d9ce377a_e
Fix from $2,300 2024-05-02
Script Security HIGH 8.8
CVE-2024-34145

A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1…

Fix: after 1335.vf07d9ce377a_e
Fix from $1,950 2024-05-02
Subversion Partial Release Manager MEDIUM 6.8
CVE-2024-34148

Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered…

Fix: after 1.0.1
Fix from $1,600 2024-05-02
Git Server MEDIUM 6.5
CVE-2024-34146

Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git repository over SSH, allowing a…

Fix: after 114.v068a_c7cc2574
Fix from $1,600 2024-05-02
Icescrum HIGH 8.8
CVE-2024-28160

Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vu…

Fix: after 1.1.6
Fix from $1,950 2024-03-06
Docker Build Step HIGH 8.8
CVE-2024-2216

A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to …

Fix: after 2.11
Fix from $1,950 2024-03-06
Docker Build Step MEDIUM 6.1
CVE-2024-2215

A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-spe…

Fix: after 2.11
Fix from $1,600 2024-03-06
Delphix MEDIUM 5.3
CVE-2024-28161

In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) …

Mitigation only
Fix from $1,600 2024-03-06
Gitbucket HIGH 8.0
CVE-2024-28157

Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerabil…

Fix: after 0.8
Fix from $1,950 2024-03-06
Html Publisher MEDIUM 6.5
CVE-2024-28149

Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission …

Fix: 1.32.1+
Fix from $1,600 2024-03-06
Mq Notifier MEDIUM 6.5
CVE-2024-28154

Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.

Fix: 1.4.1+
Fix from $1,600 2024-03-06
Bitbucket Branch Source MEDIUM 6.3
CVE-2024-28152

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks…

Fix: 848.850.v6a_a_2a_234a_c81+
Fix from $1,600 2024-03-06
Owasp Dependency Check MEDIUM 5.4
CVE-2024-28153

Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored c…

Fix: 5.4.6+
Fix from $1,600 2024-03-06
Build Monitor View MEDIUM 5.4
CVE-2024-28156EPSS 80%

Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scri…

Fix: after 1.14-860.vd06ef2568b_3f
Fix from $1,600 2024-03-06
Jenkins CRITICAL 9.8
CVE-2024-23897 KEVEPSS 100%

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a …

Fix: 2.426.3 / 2.442+
Fix from $2,300 2024-01-24
Jenkins HIGH 8.8
CVE-2024-23898EPSS 67%

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made throug…

Fix: after 2.441
Fix from $1,950 2024-01-24
Log Command HIGH 7.5
CVE-2024-23904

Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path …

Fix: after 1.0.2
Fix from $1,950 2024-01-24
Git Server MEDIUM 6.5
CVE-2024-23899

Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed b…

Fix: after 99.va_0826a_b_cdfa_d
Fix from $1,600 2024-01-24
Github Branch Source MEDIUM 6.5
CVE-2024-23901

Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner grou…

Fix: after 684.vea_fa_7c1e2fe3
Fix from $1,600 2024-01-24
Red Hat Dependency Analytics MEDIUM 5.4
CVE-2024-23905

Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content…

Fix: after 0.7.1
Fix from $1,600 2024-01-24
Github Branch Source MEDIUM 5.3
CVE-2024-23903

Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided a…

Fix: after 684.vea_fa_7c1e2fe3
Fix from $1,600 2024-01-24
Paaslane Estimate HIGH 8.8
CVE-2023-50778

A cross-site request forgery (CSRF) vulnerability in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allows attackers to connect to an attacker-sp…

Fix: after 1.0.4
Fix from $1,950 2023-12-13
Html Resource HIGH 8.1
CVE-2023-50774

A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin 1.02 and earlier allows attackers to delete arbitrary files on the J…

Mitigation only
Fix from $1,950 2023-12-13
Openid MEDIUM 6.7
CVE-2023-50770

Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverab…

Fix: after 2.6
Fix from $1,600 2023-12-13
Openid Connect Authentication MEDIUM 6.1
CVE-2023-50771

Jenkins OpenId Connect Authentication Plugin 2.6 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkin…

Fix: after 2.6
Fix from $1,600 2023-12-13
Nexus Platform HIGH 8.8
CVE-2023-50766

A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to send an HTTP request to …

Fix: after 3.18.0-03
Fix from $1,950 2023-12-13