CVE-2017-2608
- EPSS 3.13%
- Published 15.05.2018 20:29:00
- Last modified 21.11.2024 03:23:49
Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserialization of various types in javax.imageio in XStream-based APIs (SECURITY-383).
CVE-2017-2612
- EPSS 0.12%
- Published 15.05.2018 20:29:00
- Last modified 21.11.2024 03:23:49
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds possibly failing to download a JDK.
CVE-2017-2601
- EPSS 0.26%
- Published 10.05.2018 13:29:00
- Last modified 21.11.2024 03:23:48
Jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in parameter names and descriptions (SECURITY-353). Users with the permission to configure jobs were able to inject JavaScript into parameter names and description...
CVE-2017-2606
- EPSS 0.08%
- Published 08.05.2018 20:29:00
- Last modified 21.11.2024 03:23:48
Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that should not be visible (SECURITY-380). This only affects anonymous users (other users legitimately have access) tha...
CVE-2017-2611
- EPSS 0.29%
- Published 08.05.2018 18:29:00
- Last modified 21.11.2024 03:23:49
Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jen...
CVE-2018-1000170
- EPSS 0.22%
- Published 16.04.2018 09:58:09
- Last modified 21.11.2024 03:39:50
A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name containing Java...
CVE-2018-1000169
- EPSS 0.19%
- Published 16.04.2018 09:58:08
- Last modified 21.11.2024 03:39:50
An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler.java that allows unauthorized attackers to confirm the existence of agents or views with an attacker...
CVE-2017-2599
- EPSS 0.16%
- Published 11.04.2018 16:29:00
- Last modified 21.11.2024 03:23:48
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURITY-321).
CVE-2018-6356
- EPSS 37.85%
- Published 20.02.2018 15:29:00
- Last modified 21.11.2024 04:10:32
Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Je...
CVE-2018-1000067
- EPSS 0.35%
- Published 16.02.2018 00:29:01
- Last modified 21.11.2024 03:39:33
An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.