Jenkins

Jenkins

251 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.53%
  • Published 15.07.2020 18:15:37
  • Last modified 21.11.2024 05:25:00

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.

  • EPSS 0.53%
  • Published 15.07.2020 18:15:37
  • Last modified 21.11.2024 05:25:00

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.

  • EPSS 0.43%
  • Published 15.07.2020 18:15:36
  • Last modified 21.11.2024 05:24:59

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.

  • EPSS 0.3%
  • Published 25.03.2020 17:15:15
  • Last modified 21.11.2024 05:24:49

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to defin...

  • EPSS 0.43%
  • Published 25.03.2020 17:15:15
  • Last modified 21.11.2024 05:24:49

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.

  • EPSS 0.43%
  • Published 25.03.2020 17:15:15
  • Last modified 21.11.2024 05:24:50

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerability exploitable by users able to control column headers.

  • EPSS 0.2%
  • Published 25.03.2020 17:15:14
  • Last modified 21.11.2024 05:24:49

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.

  • EPSS 1.94%
  • Published 24.02.2020 17:15:13
  • Last modified 21.11.2024 01:35:43

Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "th...

  • EPSS 0.64%
  • Published 29.01.2020 16:15:12
  • Last modified 21.11.2024 05:24:37

Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which...

  • EPSS 1.37%
  • Published 29.01.2020 16:15:12
  • Last modified 21.11.2024 05:24:37

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848.