Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-41935
Jenkins Azure AD Plugin 396.v86ce29279947 and previous versions, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing malicious users to use statistical ...
Jenkins Azure Ad
NA
CVE-2023-41936
Jenkins Google Login Plugin 1.7 and previous versions uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing malicious users to use statistical methods to obtain a valid token.
Jenkins Google Login
NA
CVE-2023-41938
A cross-site request forgery (CSRF) vulnerability in Jenkins Ivy Plugin 2.5 and previous versions allows malicious users to delete disabled modules.
Jenkins Ivy
NA
CVE-2023-41939
Jenkins SSH2 Easy Plugin 1.4 and previous versions does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.
Jenkins Ssh2 Easy
NA
CVE-2023-41940
Jenkins TAP Plugin 2.3 and previous versions does not escape TAP file contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control TAP file contents.
Jenkins Tap
NA
CVE-2023-41941
A missing permission check in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and previous versions allows attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins.
Jenkins Aws Codecommit Trigger
NA
CVE-2023-41942
A cross-site request forgery (CSRF) vulnerability in Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and previous versions allows malicious users to clear the SQS queue.
Jenkins Aws Codecommit Trigger
NA
CVE-2023-41943
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and previous versions does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to clear the SQS queue.
Jenkins Aws Codecommit Trigger
NA
CVE-2023-41944
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and previous versions does not escape the queue name parameter passed to a form validation URL, when rendering an error message, resulting in an HTML injection vulnerability.
Jenkins Aws Codecommit Trigger
NA
CVE-2023-41945
Jenkins Assembla Auth Plugin 1.14 and previous versions does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be g...
Jenkins Assembla Auth
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »