CVE-2023-27902
- EPSS 0.22%
- Published 10.03.2023 21:15:15
- Last modified 28.02.2025 19:15:35
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier shows temporary directories related to job workspaces, which allows attackers with Item/Workspace permission to access their contents.
CVE-2023-27903
- EPSS 0.04%
- Published 10.03.2023 21:15:15
- Last modified 28.02.2025 19:15:35
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a file parameter through the CLI, potentially allowing attackers with a...
CVE-2023-27904
- EPSS 0.16%
- Published 10.03.2023 21:15:15
- Last modified 28.02.2025 19:15:35
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise inaccessible to attackers.
CVE-2022-41224
- EPSS 2.13%
- Published 21.09.2022 16:15:09
- Last modified 28.05.2025 16:15:28
Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to contr...
CVE-2022-2048
- EPSS 1.33%
- Published 07.07.2022 21:15:10
- Last modified 21.11.2024 07:00:13
In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service s...
CVE-2022-34170
- EPSS 5.05%
- Published 23.06.2022 17:15:15
- Last modified 21.11.2024 07:08:59
In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site ...
CVE-2022-34171
- EPSS 4.33%
- Published 23.06.2022 17:15:15
- Last modified 21.11.2024 07:08:59
In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of '...
CVE-2022-34172
- EPSS 6.4%
- Published 23.06.2022 17:15:15
- Last modified 21.11.2024 07:08:59
In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.
CVE-2022-34173
- EPSS 11.82%
- Published 23.06.2022 17:15:15
- Last modified 21.11.2024 07:09:00
In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure per...
CVE-2022-34174
- EPSS 1.7%
- Published 23.06.2022 17:15:15
- Last modified 21.11.2024 07:09:00
In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using t...