Jenkins

Jenkins

256 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 23.07.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:01

A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date ...

  • EPSS 0.16%
  • Veröffentlicht 23.07.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:01

A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to d...

  • EPSS 0.48%
  • Veröffentlicht 05.06.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:39:53

A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.

  • EPSS 0.76%
  • Veröffentlicht 05.06.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:39:54

A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear ...

  • EPSS 0.47%
  • Veröffentlicht 05.06.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:39:54

A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master secu...

  • EPSS 0.7%
  • Veröffentlicht 05.06.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:39:54

A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn...

  • EPSS 0.06%
  • Veröffentlicht 23.05.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:23:48

Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).

  • EPSS 0.08%
  • Veröffentlicht 22.05.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:23:49

jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autocomplete feature on the search box discloses the names of the views in its suggestions, including the ones for...

  • EPSS 0.05%
  • Veröffentlicht 21.05.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:23:49

jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting vulnerability in console notes (SECURITY-382). Jenkins allows plugins to annotate build logs, adding new content or changing the presentation of existing content w...

  • EPSS 0.06%
  • Veröffentlicht 15.05.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:23:49

jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record was only retained until restart in most cases, administrators' web browsers could be manipulated to create a large number of user r...