Lucene search

K

Jenkins Security Vulnerabilities

cve
cve

CVE-2023-32988

A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

4.3CVSS

4.3AI Score

0.0005EPSS

2023-05-16 04:15 PM
26
cve
cve

CVE-2023-32989

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method.

8.8CVSS

8.6AI Score

0.001EPSS

2023-05-16 04:15 PM
25
cve
cve

CVE-2023-32990

A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method.

6.5CVSS

6.2AI Score

0.0005EPSS

2023-05-16 05:15 PM
26
cve
cve

CVE-2023-32991

A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML.

8.8CVSS

8.5AI Score

0.001EPSS

2023-05-16 05:15 PM
21
cve
cve

CVE-2023-32992

Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML.

8.8CVSS

8.4AI Score

0.001EPSS

2023-05-16 05:15 PM
22
cve
cve

CVE-2023-32993

Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.

4.8CVSS

4.9AI Score

0.0005EPSS

2023-05-16 05:15 PM
20
cve
cve

CVE-2023-32994

Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 and earlier unconditionally disables SSL/TLS certificate validation for connections to miniOrange or the configured IdP to retrieve SAML metadata, which could be abused using a man-in-the-middle attack to intercept these connections.

3.7CVSS

4.1AI Score

0.0005EPSS

2023-05-16 05:15 PM
24
cve
cve

CVE-2023-32995

A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers to send an HTTP POST request with JSON body containing attacker-specified content, to miniOrange's API for sending emails.

8.8CVSS

8.7AI Score

0.001EPSS

2023-05-16 05:15 PM
19
cve
cve

CVE-2023-32996

A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request with JSON body containing attacker-specified content, to miniOrange's API for sending emails.

4.3CVSS

4.5AI Score

0.0005EPSS

2023-05-16 05:15 PM
20
cve
cve

CVE-2023-32997

Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login.

8.8CVSS

8.6AI Score

0.002EPSS

2023-05-16 05:15 PM
26
cve
cve

CVE-2023-32998

A cross-site request forgery (CSRF) vulnerability in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers to connect to an attacker-specified URL and send an HTTP POST request with a JSON payload consisting of attacker-specified credentials.

8.8CVSS

8.6AI Score

0.001EPSS

2023-05-16 05:15 PM
19
cve
cve

CVE-2023-32999

A missing permission check in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL and send an HTTP POST request with a JSON payload consisting of attacker-specified credentials.

4.3CVSS

4.4AI Score

0.0005EPSS

2023-05-16 05:15 PM
20
cve
cve

CVE-2023-33000

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them.

7.5CVSS

7.5AI Score

0.001EPSS

2023-05-16 05:15 PM
19
cve
cve

CVE-2023-33001

Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.

7.5CVSS

7.5AI Score

0.001EPSS

2023-05-16 05:15 PM
29
cve
cve

CVE-2023-33002

Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2023-05-16 05:15 PM
19
cve
cve

CVE-2023-33003

A cross-site request forgery (CSRF) vulnerability in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers to reset profiler statistics.

4.3CVSS

4.5AI Score

0.0005EPSS

2023-05-16 05:15 PM
20
cve
cve

CVE-2023-33004

A missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission to reset profiler statistics.

4.3CVSS

4.4AI Score

0.0005EPSS

2023-05-16 05:15 PM
20
cve
cve

CVE-2023-33005

Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.

5.4CVSS

5.5AI Score

0.0005EPSS

2023-05-16 05:15 PM
17
cve
cve

CVE-2023-33006

A cross-site request forgery (CSRF) vulnerability in Jenkins WSO2 Oauth Plugin 1.0 and earlier allows attackers to trick users into logging in to the attacker's account.

5.4CVSS

5.4AI Score

0.0005EPSS

2023-05-16 05:15 PM
20
cve
cve

CVE-2023-33007

Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2023-05-16 05:15 PM
21
cve
cve

CVE-2023-3315

Missing permission checks in Jenkins Team Concert Plugin 2.4.1 and earlier allow attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

4.3CVSS

4.4AI Score

0.0005EPSS

2023-06-19 09:15 PM
37
cve
cve

CVE-2023-3414

A cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceN...

6.5CVSS

6.4AI Score

0.001EPSS

2023-07-26 07:15 PM
215
cve
cve

CVE-2023-3442

A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow De...

7.7CVSS

7.4AI Score

0.001EPSS

2023-07-26 07:15 PM
218
cve
cve

CVE-2023-35141

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context men...

8CVSS

7.5AI Score

0.001EPSS

2023-06-14 01:15 PM
51
cve
cve

CVE-2023-35142

Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.

8.1CVSS

7.9AI Score

0.002EPSS

2023-06-14 01:15 PM
25
cve
cve

CVE-2023-35143

Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape the versions of build artifacts on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control maven project versions in pom.xml.

5.4CVSS

5.2AI Score

0.001EPSS

2023-06-14 01:15 PM
23
cve
cve

CVE-2023-35144

Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape project and build display names on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability.

5.4CVSS

5.2AI Score

0.001EPSS

2023-06-14 01:15 PM
25
cve
cve

CVE-2023-35145

Jenkins Sonargraph Integration Plugin 5.0.1 and earlier does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.1AI Score

0.001EPSS

2023-06-14 01:15 PM
38
cve
cve

CVE-2023-35146

Jenkins Template Workflows Plugin 41.v32d86a_313b_4a and earlier does not escape names of jobs used as buildings blocks for Template Workflow Job, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create jobs.

5.4CVSS

5.2AI Score

0.001EPSS

2023-06-14 01:15 PM
28
cve
cve

CVE-2023-35147

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attackers with Item/Read permission to obtain the contents of arbitrary files on the Jenkins controller file system.

6.5CVSS

6.2AI Score

0.001EPSS

2023-06-14 01:15 PM
36
cve
cve

CVE-2023-35148

A cross-site request forgery (CSRF) vulnerability in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

6.5CVSS

6.3AI Score

0.001EPSS

2023-06-14 01:15 PM
29
cve
cve

CVE-2023-35149

A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

6.5CVSS

6.2AI Score

0.001EPSS

2023-06-14 01:15 PM
35
cve
cve

CVE-2023-36478

Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an integer overflow in MetaDataBuilder.checkSize allows for HTTP/2 HPACK header values toexceed their size limit. MetaDataBuilder.java determines if a hea...

7.5CVSS

7.5AI Score

0.004EPSS

2023-10-10 05:15 PM
406
cve
cve

CVE-2023-37942

Jenkins External Monitor Job Type Plugin 206.v9a_94ff0b_4a_10 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

6.5CVSS

6.4AI Score

0.0005EPSS

2023-07-12 04:15 PM
18
cve
cve

CVE-2023-37943

Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active ...

5.9CVSS

5.5AI Score

0.001EPSS

2023-07-12 04:15 PM
20
cve
cve

CVE-2023-37944

A missing permission check in Jenkins Datadog Plugin 5.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

6.5CVSS

6.2AI Score

0.001EPSS

2023-07-12 04:15 PM
18
cve
cve

CVE-2023-37945

A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attackers with Overall/Read permission to download a string representation of the current security realm.

4.3CVSS

4.4AI Score

0.0005EPSS

2023-07-12 04:15 PM
12
cve
cve

CVE-2023-37946

Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login.

8.8CVSS

8.6AI Score

0.001EPSS

2023-07-12 04:15 PM
23
cve
cve

CVE-2023-37947

Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.

6.1CVSS

6.1AI Score

0.001EPSS

2023-07-12 04:15 PM
27
cve
cve

CVE-2023-37948

Jenkins Oracle Cloud Infrastructure Compute Plugin 1.0.16 and earlier does not validate SSH host keys when connecting OCI clouds, enabling man-in-the-middle attacks.

3.7CVSS

4.1AI Score

0.001EPSS

2023-07-12 04:15 PM
20
cve
cve

CVE-2023-37949

A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

7.1CVSS

6.7AI Score

0.001EPSS

2023-07-12 04:15 PM
12
cve
cve

CVE-2023-37950

A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

4.3CVSS

4.4AI Score

0.0005EPSS

2023-07-12 04:15 PM
14
cve
cve

CVE-2023-37951

Jenkins mabl Plugin 0.0.46 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.

6.5CVSS

6.4AI Score

0.001EPSS

2023-07-12 04:15 PM
11
cve
cve

CVE-2023-37952

A cross-site request forgery (CSRF) vulnerability in Jenkins mabl Plugin 0.0.46 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

6.5CVSS

6.4AI Score

0.0005EPSS

2023-07-12 04:15 PM
18
cve
cve

CVE-2023-37953

A missing permission check in Jenkins mabl Plugin 0.0.46 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

6.5CVSS

6.3AI Score

0.001EPSS

2023-07-12 04:15 PM
13
cve
cve

CVE-2023-37954

A cross-site request forgery (CSRF) vulnerability in Jenkins Rebuilder Plugin 320.v5a_0933a_e7d61 and earlier allows attackers to rebuild a previous build.

4.3CVSS

4.5AI Score

0.0005EPSS

2023-07-12 04:15 PM
18
cve
cve

CVE-2023-37955

A cross-site request forgery (CSRF) vulnerability in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.

6.5CVSS

6.4AI Score

0.0005EPSS

2023-07-12 04:15 PM
15
cve
cve

CVE-2023-37956

A missing permission check in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

6.5CVSS

6.3AI Score

0.0005EPSS

2023-07-12 04:15 PM
18
cve
cve

CVE-2023-37957

A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline restFul API Plugin 0.11 and earlier allows attackers to connect to an attacker-specified URL, capturing a newly generated JCLI token.

8.8CVSS

8.6AI Score

0.001EPSS

2023-07-12 04:15 PM
2414
cve
cve

CVE-2023-37958

A cross-site request forgery (CSRF) vulnerability in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attackers to connect to an attacker-specified URL.

8.8CVSS

8.7AI Score

0.0005EPSS

2023-07-12 04:15 PM
17
Total number of security vulnerabilities1603