CVE-2025-27624
- EPSS 0.43%
- Veröffentlicht 05.03.2025 23:15:14
- Zuletzt bearbeitet 24.06.2025 00:45:20
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of sidepanel widgets (e.g., Build Queue and Build Executor Status widgets).
CVE-2025-27625
- EPSS 0.6%
- Veröffentlicht 05.03.2025 23:15:14
- Zuletzt bearbeitet 24.06.2025 00:42:16
In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different si...
CVE-2025-27622
- EPSS 0.75%
- Veröffentlicht 05.03.2025 23:15:13
- Zuletzt bearbeitet 24.06.2025 00:48:40
Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowing attackers with Agent/Extended Read permission to view encrypted values of secrets.
CVE-2024-47803
- EPSS 0.82%
- Veröffentlicht 02.10.2024 16:15:10
- Zuletzt bearbeitet 19.03.2025 18:15:23
Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form field.
CVE-2024-47804
- EPSS 0.67%
- Veröffentlicht 02.10.2024 16:15:10
- Zuletzt bearbeitet 14.03.2025 16:15:36
If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2...
CVE-2024-43044
- EPSS 28.78%
- Veröffentlicht 07.08.2024 14:15:33
- Zuletzt bearbeitet 14.03.2025 20:15:13
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.
CVE-2024-43045
- EPSS 4.26%
- Veröffentlicht 07.08.2024 14:15:33
- Zuletzt bearbeitet 25.03.2025 17:16:05
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to access other users' "My Views".
CVE-2024-34148
- EPSS 0.79%
- Veröffentlicht 02.05.2024 14:15:10
- Zuletzt bearbeitet 06.06.2025 15:28:57
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefined...
CVE-2024-23897
- EPSS 100%
- Veröffentlicht 24.01.2024 18:15:09
- Zuletzt bearbeitet 24.10.2025 14:49:09
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitra...
CVE-2024-23898
- EPSS 67.15%
- Veröffentlicht 24.01.2024 18:15:09
- Zuletzt bearbeitet 21.11.2024 08:58:39
Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, al...