Jenkins

Jenkins

274 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 10.08.2026 12:07:02
  • Zuletzt bearbeitet 13.08.2026 12:17:23

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • EPSS 0.17%
  • Veröffentlicht 05.08.2026 17:40:29
  • Zuletzt bearbeitet 06.08.2026 16:16:52

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate...

  • EPSS 0.17%
  • Veröffentlicht 05.08.2026 17:40:29
  • Zuletzt bearbeitet 06.08.2026 16:16:52

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types ...

  • EPSS 0.25%
  • Veröffentlicht 05.08.2026 17:40:28
  • Zuletzt bearbeitet 05.08.2026 19:17:35

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the contr...

  • EPSS 0.29%
  • Veröffentlicht 05.08.2026 17:40:27
  • Zuletzt bearbeitet 06.08.2026 05:17:05

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserializatio...

  • EPSS 0.25%
  • Veröffentlicht 05.08.2026 17:40:27
  • Zuletzt bearbeitet 05.08.2026 19:17:35

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archiv...

  • EPSS 0.19%
  • Veröffentlicht 10.06.2026 13:06:02
  • Zuletzt bearbeitet 12.06.2026 00:59:52

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users wit...

  • EPSS 0.26%
  • Veröffentlicht 10.06.2026 13:06:01
  • Zuletzt bearbeitet 06.07.2026 16:16:34

Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site ...

  • EPSS 0.23%
  • Veröffentlicht 10.06.2026 13:06:00
  • Zuletzt bearbeitet 11.06.2026 13:06:36

Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".

  • EPSS 0.24%
  • Veröffentlicht 10.06.2026 13:06:00
  • Zuletzt bearbeitet 12.06.2026 01:03:40

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users...