Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Script Security HIGH 7.3
CVE-2016-3102

The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that pe…

Mitigation only
Fix from $1,950 2017-02-09
Image Gallery MEDIUM 6.5
CVE-2016-4987

Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read ar…

Fix: 1.4+
Fix from $1,600 2017-02-09
Build Failure Analyzer MEDIUM 6.1
CVE-2016-4988

Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary we…

Fix: 1.16.0+
Fix from $1,600 2017-02-09
Extra Columns MEDIUM 5.4
CVE-2016-3101

Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to inject arbitrary web script or…

Fix: 1.17+
Fix from $1,600 2017-02-09
Jenkins CRITICAL 9.8
CVE-2016-9299EPSS 97%

The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java obje…

Fix: after 2.31
Fix from $2,300 2017-01-12
Jenkins HIGH 7.4
CVE-2016-3726

Multiple open redirect vulnerabilities in Jenkins before 2.3 and LTS before 1.651.2 allow remote attackers to redirect users to arbitrary web sites a…

Fix: after 2.2
Fix from $1,950 2016-05-17
Jenkins HIGH 8.8
CVE-2016-0792EPSS 83%

Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via seri…

Fix: after 1.649
Fix from $1,950 2016-04-07
Jenkins MEDIUM 6.1
CVE-2016-0789

CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitr…

Fix: after 1.649
Fix from $1,600 2016-04-07
Jenkins MEDIUM 5.3
CVE-2016-0790

Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to …

Fix: after 1.649
Fix from $1,600 2016-04-07
Jenkins CRITICAL 9.8
CVE-2016-0788EPSS 12%

The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.

Fix: after 1.649
Fix from $2,300 2016-04-07
Jenkins HIGH 7.5
CVE-2015-7539

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which m…

Fix: after 1.639
Fix from $1,950 2016-02-03
Jenkins HIGH 8.8
CVE-2015-7538

Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.

Fix: after 3.1
Fix from $1,950 2016-02-03
Jenkins MEDIUM 5.4
CVE-2015-7536

Cross-site scripting (XSS) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote authenticated users to inject arbitrary web scr…

Fix: after 1.639
Fix from $1,600 2016-02-03
Jenkins MEDIUM 5.0
CVE-2015-5324

Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.

Fix: after 3.1
Fix from $1,600 2015-11-25
Jenkins MEDIUM 6.8
CVE-2015-5318

Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protection tokens, which makes it easier for remote atta…

Fix: after 3.1
Fix from $1,600 2015-11-25
Jenkins HIGH 7.5
CVE-2015-5317 KEVEPSS 22%

The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information…

Fix: after 3.1
Fix from $1,950 2015-11-25
Jenkins MEDIUM 6.8
CVE-2014-3665

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers t…

Fix: after 1.586
Fix from $1,600 2015-11-25
Jenkins HIGH 7.5
CVE-2015-1814

The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token chang…

Fix: after 3.1
Fix from $1,950 2015-10-16
Jenkins MEDIUM 6.5
CVE-2015-1806

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permissi…

Fix: after 3.1
Fix from $1,600 2015-10-16
Jenkins HIGH 7.5
CVE-2014-2063

Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

Fix: after 1.550
Fix from $1,950 2014-10-17
Jenkins MEDIUM 6.8
CVE-2014-2066

Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving th…

Fix: after 1.550
Fix from $1,600 2014-10-17
Jenkins MEDIUM 6.5
CVE-2014-2058

BuildTrigger in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to bypass access restrictions and execute arbitrary job…

Fix: after 1.550
Fix from $1,600 2014-10-17
Jenkins MEDIUM 6.5
CVE-2014-2062

Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to reta…

Fix: after 1.550
Fix from $1,600 2014-10-17
Jenkins MEDIUM 5.0
CVE-2014-2060

The Winstone servlet container in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack sessions via unspecified vectors.

Fix: after 1.550
Fix from $1,600 2014-10-17
Jenkins MEDIUM 5.0
CVE-2014-2061

The input control in PasswordParameterDefinition in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to obtain passwords by readin…

Fix: after 1.550
Fix from $1,600 2014-10-17
Jenkins MEDIUM 5.0
CVE-2014-2064

The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attac…

Fix: after 1.550
Fix from $1,600 2014-10-17
Jenkins MEDIUM 6.0
CVE-2014-3663

Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and c…

Fix: after 3.1
Fix from $1,600 2014-10-16
Jenkins MEDIUM 5.0
CVE-2014-3662

Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts.

Fix: after 3.1
Fix from $1,600 2014-10-16
Jenkins MEDIUM 6.5
CVE-2014-2059

Directory traversal vulnerability in the CLI job creation (hudson/cli/CreateJobCommand.java) in Jenkins before 1.551 and LTS before 1.532.2 allows re…

Fix: after 1.550
Fix from $1,600 2014-03-01
Jenkins HIGH 7.5
CVE-2013-0329

Unspecified vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to bypass the CSRF protection mechanism via unknown …

Fix: after 1.501
Fix from $1,950 2013-03-19