Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2021-21696
Jenkins 2.318 and previous versions, LTS 2.303.2 and previous versions does not limit agent read/write access to the libs/ directory inside build directories when using the FilePath APIs, allowing attackers in control of agent processes to replace the code of a trusted library wi...
Jenkins Jenkins
9.1
CVSSv3
CVE-2021-21697
Jenkins 2.318 and previous versions, LTS 2.303.2 and previous versions allows any agent to read and write the contents of any build directory stored in Jenkins with very few restrictions.
Jenkins Jenkins
NA
CVE-2013-0328
Cross-site scripting (XSS) vulnerability in Jenkins prior to 1.502 and LTS prior to 1.480.3 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Jenkins Jenkins
NA
CVE-2013-0329
Unspecified vulnerability in Jenkins prior to 1.502 and LTS prior to 1.480.3 allows remote malicious users to bypass the CSRF protection mechanism via unknown attack vectors.
Jenkins Jenkins
NA
CVE-2013-0331
Jenkins prior to 1.502 and LTS prior to 1.480.3 allows remote authenticated users with write access to cause a denial of service via a crafted payload.
Jenkins Jenkins
5.4
CVSSv3
CVE-2022-41224
Jenkins 2.367 up to and including 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for th...
Jenkins Jenkins
5.3
CVSSv3
CVE-2018-1999042
A vulnerability exists in Jenkins 2.137 and previous versions, 2.121.2 and previous versions in XStream2.java that allows malicious users to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.
Jenkins Jenkins
6.5
CVSSv3
CVE-2018-1999044
A denial of service vulnerability exists in Jenkins 2.137 and previous versions, 2.121.2 and previous versions in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
Jenkins Jenkins
7.5
CVSSv3
CVE-2018-1999043
A denial of service vulnerability exists in Jenkins 2.137 and previous versions, 2.121.2 and previous versions in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows malicious users to create ephemeral in-memory user records by attempting to log in u...
Jenkins Jenkins
5.3
CVSSv3
CVE-2014-9635
Jenkins prior to 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote malicious users to obtain potentially sensitive information via script access to cookies.
Jenkins Jenkins
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
logic flaw
CVE-2024-23692
CVE-2024-26229
CVE-2024-35255
CVE-2024-5835
CVE-2024-5837
XML external entity
dos
CVE-2024-5813
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »