Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2018-1000407
A cross-site scripting vulnerability exists in Jenkins 2.145 and previous versions, LTS 2.138.1 and previous versions in core/src/main/java/hudson/model/Api.java that allows malicious users to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by ...
Jenkins Jenkins
7.8
CVSSv3
CVE-2018-1000410
An information exposure vulnerability exists in Jenkins 2.145 and previous versions, LTS 2.138.1 and previous versions, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/model/Descriptor.java th...
Jenkins Jenkins
6.5
CVSSv3
CVE-2018-1000997
A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and previous versions, LTS 2.138.1 and previous versions in core/src/main/java/org/kohsuke/stapler/Facet.java, groovy/src/main/java/org/kohsuke/stapler/jelly/groovy/GroovyFacet.java, jelly/sr...
Jenkins Jenkins
6.5
CVSSv3
CVE-2019-10352
A path traversal vulnerability in Jenkins 2.185 and previous versions, LTS 2.176.1 and previous versions in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the intended dir...
Jenkins Jenkins
5.4
CVSSv3
CVE-2019-10401
In Jenkins 2.196 and previous versions, LTS 2.176.3 and previous versions, the f:expandableTextBox form control interpreted its content as HTML when expanded, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents (typically Job/Config...
Jenkins Jenkins
5.4
CVSSv3
CVE-2019-10402
In Jenkins 2.196 and previous versions, LTS 2.176.3 and previous versions, the f:combobox form control interpreted its item labels as HTML, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents.
Jenkins Jenkins
5.4
CVSSv3
CVE-2019-10403
Jenkins 2.196 and previous versions, LTS 2.176.3 and previous versions did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions.
Jenkins Jenkins
5.4
CVSSv3
CVE-2019-10405
Jenkins 2.196 and previous versions, LTS 2.176.3 and previous versions printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers exploiting another XSS vulnerability to obtain the HTTP session cookie despite it being marked HttpOnly.
Jenkins Jenkins
5.3
CVSSv3
CVE-2014-9634
Jenkins prior to 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote malicious users to capture cookies by intercepting their transmission within an HTTP session.
Jenkins Jenkins
5.3
CVSSv3
CVE-2014-9635
Jenkins prior to 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote malicious users to obtain potentially sensitive information via script access to cookies.
Jenkins Jenkins
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48654
CVE-2024-2757
authentication bypass
CVE-2024-3194
CVE-2024-33640
CVE-2024-21111
dos
insecure direct object reference
CVE-2024-21345
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »