Jenkins

Jenkins

287 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 02.09.2026 15:40:46
  • Zuletzt bearbeitet 15.09.2026 18:06:43

A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to.

  • EPSS 0.17%
  • Veröffentlicht 02.09.2026 15:40:46
  • Zuletzt bearbeitet 15.09.2026 18:05:47

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel ...

  • EPSS 0.19%
  • Veröffentlicht 02.09.2026 15:40:45
  • Zuletzt bearbeitet 15.09.2026 18:07:05

Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API re...

  • EPSS 0.16%
  • Veröffentlicht 02.09.2026 15:40:44
  • Zuletzt bearbeitet 15.09.2026 18:15:37

Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance confi...

  • EPSS 0.2%
  • Veröffentlicht 02.09.2026 15:40:44
  • Zuletzt bearbeitet 03.09.2026 17:13:16

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuration object, allowing attackers w...

  • EPSS 0.21%
  • Veröffentlicht 02.09.2026 15:40:43
  • Zuletzt bearbeitet 11.09.2026 21:16:20

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML do...

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 02.09.2026 15:40:43
  • Zuletzt bearbeitet 11.09.2026 21:09:18

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie i...

Medienbericht
  • EPSS 0.34%
  • Veröffentlicht 02.09.2026 15:40:42
  • Zuletzt bearbeitet 11.09.2026 21:16:02

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact d...

Medienbericht
  • EPSS 0.34%
  • Veröffentlicht 02.09.2026 15:40:41
  • Zuletzt bearbeitet 11.09.2026 21:14:57

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agen...

Medienbericht
  • EPSS 0.17%
  • Veröffentlicht 02.09.2026 15:40:41
  • Zuletzt bearbeitet 03.09.2026 17:13:16

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamical...