Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins jenkins vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2018-1000408
A denial of service vulnerability exists in Jenkins 2.145 and previous versions, LTS 2.138.1 and previous versions in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances usi...
Jenkins Jenkins
5.4
CVSSv3
CVE-2018-1000409
A session fixation vulnerability exists in Jenkins 2.145 and previous versions, LTS 2.138.1 and previous versions in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing session and creating a new one when a user...
Jenkins Jenkins
7.8
CVSSv3
CVE-2018-1000410
An information exposure vulnerability exists in Jenkins 2.145 and previous versions, LTS 2.138.1 and previous versions, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/model/Descriptor.java th...
Jenkins Jenkins
6.5
CVSSv3
CVE-2018-1000997
A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and previous versions, LTS 2.138.1 and previous versions in core/src/main/java/org/kohsuke/stapler/Facet.java, groovy/src/main/java/org/kohsuke/stapler/jelly/groovy/GroovyFacet.java, jelly/sr...
Jenkins Jenkins
NA
CVE-2013-0327
Cross-site request forgery (CSRF) vulnerability in Jenkins master in Jenkins prior to 1.502 and LTS prior to 1.480.3 allows remote malicious users to hijack the authentication of users via unknown vectors.
Jenkins Jenkins
NA
CVE-2013-0328
Cross-site scripting (XSS) vulnerability in Jenkins prior to 1.502 and LTS prior to 1.480.3 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Jenkins Jenkins
NA
CVE-2013-0329
Unspecified vulnerability in Jenkins prior to 1.502 and LTS prior to 1.480.3 allows remote malicious users to bypass the CSRF protection mechanism via unknown attack vectors.
Jenkins Jenkins
NA
CVE-2013-0330
Unspecified vulnerability in Jenkins prior to 1.502 and LTS prior to 1.480.3 allows remote authenticated users with write access to build arbitrary jobs via unknown attack vectors.
Jenkins Jenkins
NA
CVE-2013-0331
Jenkins prior to 1.502 and LTS prior to 1.480.3 allows remote authenticated users with write access to cause a denial of service via a crafted payload.
Jenkins Jenkins
4.3
CVSSv3
CVE-2017-2598
Jenkins prior to 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).
Jenkins Jenkins
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4367
CVE-2024-35977
CVE-2023-49335
man-in-the-middle
CVE-2024-4947
CVE-2024-31714
memory leak
SQL
CVE-2024-35994
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »