Jenkins

Jenkins

256 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 10.12.2025 16:50:38
  • Zuletzt bearbeitet 10.12.2025 18:16:23

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account.

  • EPSS -
  • Veröffentlicht 10.12.2025 16:50:37
  • Zuletzt bearbeitet 10.12.2025 18:16:22

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • EPSS -
  • Veröffentlicht 10.12.2025 16:50:36
  • Zuletzt bearbeitet 10.12.2025 18:16:22

A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.

  • EPSS -
  • Veröffentlicht 10.12.2025 16:50:36
  • Zuletzt bearbeitet 10.12.2025 18:16:22

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controlle...

  • EPSS -
  • Veröffentlicht 10.12.2025 16:50:35
  • Zuletzt bearbeitet 10.12.2025 18:16:21

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.

  • EPSS 0.09%
  • Veröffentlicht 17.09.2025 13:17:48
  • Zuletzt bearbeitet 04.11.2025 22:16:35

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters...

  • EPSS 0.26%
  • Veröffentlicht 17.09.2025 13:17:47
  • Zuletzt bearbeitet 04.11.2025 22:16:35

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent name...

  • EPSS 0.03%
  • Veröffentlicht 17.09.2025 13:17:47
  • Zuletzt bearbeitet 04.11.2025 22:16:35

Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration ...

  • EPSS 0.04%
  • Veröffentlicht 04.07.2025 08:36:35
  • Zuletzt bearbeitet 18.08.2025 19:02:46

A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a mal...

  • EPSS 0.03%
  • Veröffentlicht 02.04.2025 15:15:59
  • Zuletzt bearbeitet 29.04.2025 14:03:21

A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration.