Jenkins

Jenkins

274 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 10.06.2026 13:05:59
  • Zuletzt bearbeitet 11.06.2026 13:21:45

A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel queue items they do not have permission to view.

  • EPSS 0.36%
  • Veröffentlicht 10.06.2026 13:05:58
  • Zuletzt bearbeitet 15.07.2026 01:16:32

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks.

  • EPSS 19.04%
  • Veröffentlicht 10.06.2026 13:05:57
  • Zuletzt bearbeitet 15.07.2026 01:16:32

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle...

  • EPSS 0.28%
  • Veröffentlicht 10.06.2026 13:05:57
  • Zuletzt bearbeitet 11.06.2026 13:24:27

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), allowing attackers to perform phishing attacks.

Medienbericht
  • EPSS 0.27%
  • Veröffentlicht 18.03.2026 15:15:25
  • Zuletzt bearbeitet 21.03.2026 00:18:44

Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarde...

Medienbericht
  • EPSS 1.16%
  • Veröffentlicht 18.03.2026 15:15:23
  • Zuletzt bearbeitet 15.07.2026 02:20:02

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file sy...

  • EPSS 0.33%
  • Veröffentlicht 18.02.2026 14:17:44
  • Zuletzt bearbeitet 20.02.2026 20:53:16

Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about t...

  • EPSS 0.46%
  • Veröffentlicht 18.02.2026 14:17:43
  • Zuletzt bearbeitet 20.02.2026 20:52:03

Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability e...

  • EPSS 0.18%
  • Veröffentlicht 10.12.2025 16:50:38
  • Zuletzt bearbeitet 17.12.2025 20:23:49

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account.

  • EPSS 0.16%
  • Veröffentlicht 10.12.2025 16:50:37
  • Zuletzt bearbeitet 17.12.2025 17:37:39

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.