Jenkins

Jenkins

274 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Veröffentlicht 05.03.2025 23:15:14
  • Zuletzt bearbeitet 24.06.2025 00:45:20

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of sidepanel widgets (e.g., Build Queue and Build Executor Status widgets).

  • EPSS 0.6%
  • Veröffentlicht 05.03.2025 23:15:14
  • Zuletzt bearbeitet 24.06.2025 00:42:16

In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a Jenkins URL that will forward them to a different si...

  • EPSS 0.75%
  • Veröffentlicht 05.03.2025 23:15:13
  • Zuletzt bearbeitet 24.06.2025 00:48:40

Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowing attackers with Agent/Extended Read permission to view encrypted values of secrets.

  • EPSS 0.82%
  • Veröffentlicht 02.10.2024 16:15:10
  • Zuletzt bearbeitet 19.03.2025 18:15:23

Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form field.

  • EPSS 0.67%
  • Veröffentlicht 02.10.2024 16:15:10
  • Zuletzt bearbeitet 14.03.2025 16:15:36

If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2...

  • EPSS 28.78%
  • Veröffentlicht 07.08.2024 14:15:33
  • Zuletzt bearbeitet 14.03.2025 20:15:13

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.

  • EPSS 4.26%
  • Veröffentlicht 07.08.2024 14:15:33
  • Zuletzt bearbeitet 25.03.2025 17:16:05

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to access other users' "My Views".

  • EPSS 0.79%
  • Veröffentlicht 02.05.2024 14:15:10
  • Zuletzt bearbeitet 06.06.2025 15:28:57

Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefined...

Warnung Medienbericht Exploit
  • EPSS 100%
  • Veröffentlicht 24.01.2024 18:15:09
  • Zuletzt bearbeitet 24.10.2025 14:49:09

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitra...

  • EPSS 67.15%
  • Veröffentlicht 24.01.2024 18:15:09
  • Zuletzt bearbeitet 21.11.2024 08:58:39

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, al...