Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2023-41933
Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and previous versions does not configure its XML parser to prevent XML external entity (XXE) attacks.
Jenkins Job Configuration History
8.8
CVSSv3
CVE-2023-41939
Jenkins SSH2 Easy Plugin 1.4 and previous versions does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.
Jenkins Ssh2 Easy
8.8
CVSSv3
CVE-2023-41945
Jenkins Assembla Auth Plugin 1.14 and previous versions does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be g...
Jenkins Assembla Auth
8.8
CVSSv3
CVE-2023-40341
A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and previous versions allows malicious users to connect to an attacker-specified URL, capturing GitHub credentials associated with an attacker-specified job.
Jenkins Blue Ocean
8.8
CVSSv3
CVE-2023-40336
A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and previous versions allows malicious users to copy folders.
Jenkins Folders
8.8
CVSSv3
CVE-2023-37946
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and previous versions does not invalidate the previous session on login.
Jenkins Openshift Login
8.8
CVSSv3
CVE-2023-37957
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline restFul API Plugin 0.11 and previous versions allows malicious users to connect to an attacker-specified URL, capturing a newly generated JCLI token.
Jenkins Pipeline Restful Api
8.8
CVSSv3
CVE-2023-37958
A cross-site request forgery (CSRF) vulnerability in Jenkins Sumologic Publisher Plugin 2.2.1 and previous versions allows malicious users to connect to an attacker-specified URL.
Jenkins Sumologic Publisher
8.8
CVSSv3
CVE-2023-37961
A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Auth Plugin 1.14 and previous versions allows malicious users to trick users into logging in to the attacker's account.
Jenkins Assembla
8.8
CVSSv3
CVE-2023-37962
A cross-site request forgery (CSRF) vulnerability in Jenkins Benchmark Evaluator Plugin 1.0.1 and previous versions allows malicious users to connect to an attacker-specified URL and to check for the existence of directories, `.csv`, and `.ycsb` files on the Jenkins controller fi...
Jenkins Benchmark Evaluator
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »