Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jenkins vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv3
CVE-2018-1000410
An information exposure vulnerability exists in Jenkins 2.145 and previous versions, LTS 2.138.1 and previous versions, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/model/Descriptor.java th...
Jenkins Jenkins
5.4
CVSSv3
CVE-2015-7536
Cross-site scripting (XSS) vulnerability in Jenkins prior to 1.640 and LTS prior to 1.625.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to workspaces and archived artifacts.
Jenkins Jenkins
4.7
CVSSv3
CVE-2017-17383
Jenkins up to and including 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
Jenkins Jenkins
5.3
CVSSv3
CVE-2018-1999042
A vulnerability exists in Jenkins 2.137 and previous versions, 2.121.2 and previous versions in XStream2.java that allows malicious users to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.
Jenkins Jenkins
7.5
CVSSv3
CVE-2018-1999043
A denial of service vulnerability exists in Jenkins 2.137 and previous versions, 2.121.2 and previous versions in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows malicious users to create ephemeral in-memory user records by attempting to log in u...
Jenkins Jenkins
6.5
CVSSv3
CVE-2018-1999044
A denial of service vulnerability exists in Jenkins 2.137 and previous versions, 2.121.2 and previous versions in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
Jenkins Jenkins
5.4
CVSSv3
CVE-2018-1999045
A improper authentication vulnerability exists in Jenkins 2.137 and previous versions, 2.121.2 and previous versions in SecurityRealm.java, TokenBasedRememberMeServices2.java that allows attackers with a valid cookie to remain logged in even if that feature is disabled.
Jenkins Jenkins
4.3
CVSSv3
CVE-2018-1999046
A exposure of sensitive information vulnerability exists in Jenkins 2.137 and previous versions, 2.121.2 and previous versions in Computer.java that allows attackers With Overall/Read permission to access the connection log for any agent.
Jenkins Jenkins
6.5
CVSSv3
CVE-2018-1999047
A improper authorization vulnerability exists in Jenkins 2.137 and previous versions, 2.121.2 and previous versions in UpdateCenter.java that allows malicious users to cancel a Jenkins restart scheduled through the update center.
Jenkins Jenkins
8.8
CVSSv3
CVE-2017-1000354
Jenkins versions 2.56 and previous versions as well as 2.46.1 LTS and previous versions are vulnerable to a login command which allowed impersonating any Jenkins user. The `login` command available in the remoting-based CLI stored the encrypted user name of the successfully authe...
Jenkins Jenkins
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »