Lucene search

K

Jenkins Security Vulnerabilities

cve
cve

CVE-2021-21689

FilePath#unzip and FilePath#untar were not subject to any agent-to-controller access control in Jenkins 2.318 and earlier, LTS 2.303.2 and...

9.1CVSS

9.2AI Score

0.002EPSS

2021-11-04 05:15 PM
117
2
cve
cve

CVE-2022-27199

A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified...

4.3CVSS

4.7AI Score

0.001EPSS

2022-03-15 05:15 PM
84
cve
cve

CVE-2022-27202

Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value and description of extended choice parameters of radio buttons or check boxes type, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure...

5.4CVSS

5.4AI Score

0.001EPSS

2022-03-15 05:15 PM
92
cve
cve

CVE-2022-27196

Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure or Item/Create...

5.4CVSS

5.3AI Score

0.001EPSS

2022-03-15 05:15 PM
106
cve
cve

CVE-2021-21686

File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allowing operations to follow symbolic links to outside allowed...

8.1CVSS

8.6AI Score

0.002EPSS

2021-11-04 05:15 PM
111
cve
cve

CVE-2022-43403

A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute...

9.9CVSS

9.5AI Score

0.003EPSS

2022-10-19 04:15 PM
87
3
cve
cve

CVE-2022-43404

A sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic constructors in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the...

9.9CVSS

9.5AI Score

0.001EPSS

2022-10-19 04:15 PM
72
3
cve
cve

CVE-2022-43406

A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute...

9.9CVSS

9.5AI Score

0.001EPSS

2022-10-19 04:15 PM
71
3
cve
cve

CVE-2022-36884

The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git...

5.3CVSS

5.3AI Score

0.001EPSS

2022-07-27 03:15 PM
77
6
cve
cve

CVE-2022-36889

Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the selected...

8.8CVSS

8.6AI Score

0.001EPSS

2022-07-27 03:15 PM
51
6
cve
cve

CVE-2022-36890

Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementing form validation, allowing attackers with Item/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file...

4.3CVSS

4.4AI Score

0.001EPSS

2022-07-27 03:15 PM
58
4
cve
cve

CVE-2022-36893

Jenkins rpmsign-plugin Plugin 0.5.0 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace...

4.3CVSS

4.4AI Score

0.001EPSS

2022-07-27 03:15 PM
44
4
cve
cve

CVE-2022-34818

Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier does not perform permission checks in several views and HTTP endpoints, allowing attackers with Overall/Read permission to disable...

4.3CVSS

4.8AI Score

0.001EPSS

2022-06-30 06:15 PM
236
5
cve
cve

CVE-2022-34799

Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file...

4.3CVSS

4.9AI Score

0.001EPSS

2022-06-30 06:15 PM
244
3
cve
cve

CVE-2022-34800

Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file...

4.3CVSS

4.8AI Score

0.001EPSS

2022-06-30 06:15 PM
233
3
cve
cve

CVE-2022-34802

Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file...

4.3CVSS

4.9AI Score

0.001EPSS

2022-06-30 06:15 PM
235
3
cve
cve

CVE-2022-34803

Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission (config.xml), or access to the Jenkins controller file...

4.3CVSS

4.8AI Score

0.001EPSS

2022-06-30 06:15 PM
595
4
cve
cve

CVE-2021-43576

Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Overall/Read and Item/Read permissions to have Jenkins parse a crafted XML file that uses external entities for extraction of secrets from the Jenkins...

6.5CVSS

6.3AI Score

0.005EPSS

2021-11-12 11:15 AM
37
cve
cve

CVE-2022-20617

Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM...

8.8CVSS

8.5AI Score

0.002EPSS

2022-01-12 08:15 PM
148
cve
cve

CVE-2021-21693

When creating temporary files, agent-to-controller access to create those files is only checked after they've been created in Jenkins 2.318 and earlier, LTS 2.303.2 and...

9.8CVSS

9.2AI Score

0.002EPSS

2021-11-04 05:15 PM
117
cve
cve

CVE-2021-21679

Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in...

8.8CVSS

8.6AI Score

0.001EPSS

2021-08-31 02:15 PM
41
cve
cve

CVE-2021-21681

Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file...

5.5CVSS

5.7AI Score

0.0004EPSS

2021-08-31 02:15 PM
48
cve
cve

CVE-2022-25212

A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect to an attacker-specified web server using attacker-specified...

8.8CVSS

8.6AI Score

0.001EPSS

2022-02-15 05:15 PM
100
cve
cve

CVE-2021-21687

Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not check agent-to-controller access to create symbolic links when unarchiving a symbolic link in...

9.1CVSS

9.1AI Score

0.002EPSS

2021-11-04 05:15 PM
101
cve
cve

CVE-2022-36912

A missing permission check in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified...

4.3CVSS

4.4AI Score

0.001EPSS

2022-07-27 03:15 PM
46
4
cve
cve

CVE-2022-43402

A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5ea_628154b_c2 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection....

9.9CVSS

9.5AI Score

0.001EPSS

2022-10-19 04:15 PM
72
3
cve
cve

CVE-2022-43405

A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary...

9.9CVSS

9.5AI Score

0.001EPSS

2022-10-19 04:15 PM
56
4
cve
cve

CVE-2021-21680

Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE)...

7.1CVSS

7AI Score

0.001EPSS

2021-08-31 02:15 PM
38
cve
cve

CVE-2022-36886

A cross-site request forgery (CSRF) vulnerability in Jenkins External Monitor Job Type Plugin 191.v363d0d1efdf8 and earlier allows attackers to create runs of an external...

4.3CVSS

4.5AI Score

0.001EPSS

2022-07-27 03:15 PM
61
4
cve
cve

CVE-2022-36894

An arbitrary file write vulnerability in Jenkins CLIF Performance Testing Plugin 64.vc0d66de1dfb_f and earlier allows attackers with Overall/Read permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified...

6.5CVSS

6.4AI Score

0.001EPSS

2022-07-27 03:15 PM
51
4
cve
cve

CVE-2022-34798

Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified...

4.3CVSS

5AI Score

0.001EPSS

2022-06-30 06:15 PM
248
4
cve
cve

CVE-2022-34812

A cross-site request forgery (CSRF) vulnerability in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers to create and delete XPath...

4.3CVSS

4.9AI Score

0.001EPSS

2022-06-30 06:15 PM
244
4
cve
cve

CVE-2021-21701

Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE)...

6.5CVSS

6.3AI Score

0.002EPSS

2021-11-12 11:15 AM
46
cve
cve

CVE-2021-21692

FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier only check 'read' agent-to-controller access permission on the source path, instead of...

9.8CVSS

9.2AI Score

0.003EPSS

2021-11-04 05:15 PM
114
cve
cve

CVE-2021-21696

Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not limit agent read/write access to the libs/ directory inside build directories when using the FilePath APIs, allowing attackers in control of agent processes to replace the code of a trusted library with a modified variant. This results in....

9.8CVSS

9.4AI Score

0.003EPSS

2021-11-04 05:15 PM
119
2
cve
cve

CVE-2021-21698

Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an...

7.5CVSS

8.3AI Score

0.003EPSS

2021-11-04 05:15 PM
111
2
cve
cve

CVE-2021-21684

Jenkins Git Plugin 4.8.2 and earlier does not escape the Git SHA-1 checksum parameters provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS)...

6.1CVSS

5.7AI Score

0.001EPSS

2021-10-06 11:15 PM
77
cve
cve

CVE-2022-36911

A cross-site request forgery (CSRF) vulnerability in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers to connect to an attacker-specified...

6.5CVSS

6.4AI Score

0.001EPSS

2022-07-27 03:15 PM
56
2
cve
cve

CVE-2022-36913

Jenkins Openstack Heat Plugin 1.5 and earlier does not perform permission checks in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file...

4.3CVSS

4.5AI Score

0.001EPSS

2022-07-27 03:15 PM
50
2
cve
cve

CVE-2022-36914

Jenkins Files Found Trigger Plugin 1.5 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file...

4.3CVSS

4.4AI Score

0.001EPSS

2022-07-27 03:15 PM
56
2
cve
cve

CVE-2021-21677

Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java objects it deserializes from disk, resulting in a remote code execution...

8.8CVSS

9.1AI Score

0.004EPSS

2021-08-31 02:15 PM
46
cve
cve

CVE-2021-21678

Jenkins SAML Plugin 2.0.7 and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in...

8.8CVSS

8.6AI Score

0.001EPSS

2021-08-31 02:15 PM
42
cve
cve

CVE-2022-36888

A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified path and...

6.5CVSS

6.2AI Score

0.001EPSS

2022-07-27 03:15 PM
52
5
cve
cve

CVE-2022-36892

Jenkins rhnpush-plugin Plugin 0.5.1 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace...

4.3CVSS

4.4AI Score

0.001EPSS

2022-07-27 03:15 PM
53
4
cve
cve

CVE-2022-34808

Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file...

4.3CVSS

4.8AI Score

0.001EPSS

2022-06-30 06:15 PM
224
4
cve
cve

CVE-2022-34809

Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file...

6.5CVSS

6.7AI Score

0.001EPSS

2022-06-30 06:15 PM
239
4
cve
cve

CVE-2022-34811

A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to access the XPath Configuration Viewer...

4.3CVSS

4.7AI Score

0.001EPSS

2022-06-30 06:15 PM
231
4
cve
cve

CVE-2022-34815

A cross-site request forgery (CSRF) vulnerability in Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier allows attackers to accept pending requests, thereby renaming or deleting...

4.3CVSS

4.9AI Score

0.001EPSS

2022-06-30 06:15 PM
233
4
cve
cve

CVE-2022-34801

Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their...

4.3CVSS

5AI Score

0.001EPSS

2022-06-30 06:15 PM
238
4
cve
cve

CVE-2022-34805

Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file...

6.5CVSS

6.7AI Score

0.001EPSS

2022-06-30 06:15 PM
234
3
Total number of security vulnerabilities1653