CVE-2026-84646
- EPSS 0.24%
- Veröffentlicht 02.09.2026 15:40:40
- Zuletzt bearbeitet 11.09.2026 21:15:45
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.
CVE-2026-84647
- EPSS 0.43%
- Veröffentlicht 02.09.2026 15:40:40
- Zuletzt bearbeitet 03.09.2026 17:13:16
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compat...
CVE-2026-84645
- EPSS 0.67%
- Veröffentlicht 02.09.2026 15:40:39
- Zuletzt bearbeitet 11.09.2026 21:15:29
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in use...
CVE-2026-19429
- EPSS 0.4%
- Veröffentlicht 10.08.2026 12:07:02
- Zuletzt bearbeitet 13.08.2026 12:17:23
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-70429
- EPSS 0.17%
- Veröffentlicht 05.08.2026 17:40:29
- Zuletzt bearbeitet 08.09.2026 20:10:08
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate...
CVE-2026-70430
- EPSS 0.17%
- Veröffentlicht 05.08.2026 17:40:29
- Zuletzt bearbeitet 08.09.2026 20:04:05
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types ...
CVE-2026-70428
- EPSS 0.25%
- Veröffentlicht 05.08.2026 17:40:28
- Zuletzt bearbeitet 08.09.2026 20:15:13
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the contr...
- EPSS 0.29%
- Veröffentlicht 05.08.2026 17:40:27
- Zuletzt bearbeitet 31.08.2026 19:34:59
In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserializatio...
CVE-2026-70427
- EPSS 0.25%
- Veröffentlicht 05.08.2026 17:40:27
- Zuletzt bearbeitet 08.09.2026 20:17:23
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archiv...
CVE-2026-53442
- EPSS 0.19%
- Veröffentlicht 10.06.2026 13:06:02
- Zuletzt bearbeitet 12.06.2026 00:59:52
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users wit...