Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2022-23115 Cross-site request forgery (CSRF) vulnerabilities in Jenkins batch task Plugin 1.19 and earlier allows attackers with Overall/Read access to retrieve… Batch Task after 1.19 Fix from $1,6002022-01-12 MEDIUM 5.3 CVE-2022-23106 Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an authentication token allowing a… Configuration As Code after 1.55 Fix from $1,6002022-01-12 HIGH 8.8 CVE-2022-20617 Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability ex… Docker Commons after 1.17 Fix from $1,9502022-01-12 MEDIUM 5.4 CVE-2022-20615EPSS 82% Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a st… Matrix Project after 1.19 Fix from $1,6002022-01-12 HIGH 8.1 CVE-2021-43578 Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier implements an agent-to-controller message that does not implement any validatio… Squash Tm Publisher after 1.0.0 Fix from $1,9502021-11-12 HIGH 7.1 CVE-2021-43577 Jenkins OWASP Dependency-Check Plugin 5.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Owasp Dependency Check after 5.1.1 Fix from $1,9502021-11-12 MEDIUM 6.5 CVE-2021-21701 Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Performance after 3.20 Fix from $1,6002021-11-12 MEDIUM 6.5 CVE-2021-43576 Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Ove… Pom2config after 1.2 Fix from $1,6002021-11-12 MEDIUM 5.4 CVE-2021-21699EPSS 88% Jenkins Active Choices Plugin 2.5.6 and earlier does not escape the parameter name of reactive parameters and dynamic reference parameters, resulting… Active Choices after 2.5.6 Fix from $1,6002021-11-12 MEDIUM 5.4 CVE-2021-21700 Jenkins Scriptler Plugin 3.3 and earlier does not escape the name of scripts on the UI when asking to confirm their deletion, resulting in a stored c… Scriptler after 3.3 Fix from $1,6002021-11-12 CRITICAL 9.8 CVE-2021-21690 Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, … Jenkins 2.303.3 / 2.319+ Fix from $2,3002021-11-04 CRITICAL 9.8 CVE-2021-21691 Creating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318 and earlier, LTS 2.303.2 and… Jenkins 2.303.3 / 2.319+ Fix from $2,3002021-11-04 CRITICAL 9.8 CVE-2021-21692 FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier only check 'read' agent-to-controller access p… Jenkins 2.303.3 / 2.319+ Fix from $2,3002021-11-04 CRITICAL 9.8 CVE-2021-21693 When creating temporary files, agent-to-controller access to create those files is only checked after they've been created in Jenkins 2.318 and earli… Jenkins 2.303.3 / 2.319+ Fix from $2,3002021-11-04 CRITICAL 9.8 CVE-2021-21694 FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check any permissions in Jenkins 2… Jenkins 2.303.3 / 2.319+ Fix from $2,3002021-11-04 CRITICAL 9.8 CVE-2021-21696 Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not limit agent read/write access to the libs/ directory inside build directories when using … Jenkins after 2.318 Fix from $2,3002021-11-04 CRITICAL 9.1 CVE-2021-21687 Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic lin… Jenkins 2.303.3 / 2.319+ Fix from $2,3002021-11-04 CRITICAL 9.1 CVE-2021-21689 FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access control in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier. Jenkins 2.303.3 / 2.319+ Fix from $2,3002021-11-04 CRITICAL 9.1 CVE-2021-21697 Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to read and write the contents of any build directory stored in Jenkins with very… Jenkins after 2.318 Fix from $2,3002021-11-04 HIGH 8.8 CVE-2021-21695 FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Jenkins 2.318 and earlier, LTS … Jenkins 2.303.3 / 2.319+ Fix from $1,9502021-11-04 HIGH 8.1 CVE-2021-21686 File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allo… Jenkins 2.303.3 / 2.319+ Fix from $1,9502021-11-04 HIGH 7.5 CVE-2021-21688 The agent-to-controller security check FilePath#reading(FileVisitor) in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not reject any operat… Jenkins 2.303.3 / 2.319+ Fix from $1,9502021-11-04 HIGH 7.5 CVE-2021-21698 Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an age… Subversion after 2.15.0 Fix from $1,9502021-11-04 CRITICAL 9.1 CVE-2021-21685 Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create parent directories in FilePath#mkdirs. Jenkins 2.303.3 / 2.319+ Fix from $2,3002021-11-04 MEDIUM 6.5 CVE-2021-21683 The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on Windows, resulting in a path … Jenkins after 2.314 Fix from $1,6002021-10-06 MEDIUM 6.1 CVE-2021-21684 Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a bui… Git after 4.8.2 Fix from $1,6002021-10-06 HIGH 8.8 CVE-2021-21677 Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java objects it deserializes from dis… Code Coverage Api after 1.4.0 Fix from $1,9502021-08-31 HIGH 8.8 CVE-2021-21678 Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins. Saml after 2.0.7 Fix from $1,9502021-08-31 HIGH 8.8 CVE-2021-21679 Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenki… Azure Ad after 179.vf6841393099e Fix from $1,9502021-08-31 HIGH 7.1 CVE-2021-21680 Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) attacks. Nested View after 1.20 Fix from $1,9502021-08-31