Jenkins

Jenkins

256 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 01.09.2020 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:25:05

Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.

Exploit
  • EPSS 2.23%
  • Veröffentlicht 12.08.2020 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:25:01

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.

Exploit
  • EPSS 0.33%
  • Veröffentlicht 12.08.2020 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:25:01

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.

Exploit
  • EPSS 0.47%
  • Veröffentlicht 12.08.2020 14:15:13
  • Zuletzt bearbeitet 21.11.2024 05:25:01

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure p...

  • EPSS 0.54%
  • Veröffentlicht 15.07.2020 18:15:37
  • Zuletzt bearbeitet 21.11.2024 05:24:59

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.

  • EPSS 0.53%
  • Veröffentlicht 15.07.2020 18:15:37
  • Zuletzt bearbeitet 21.11.2024 05:25:00

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.

  • EPSS 0.53%
  • Veröffentlicht 15.07.2020 18:15:37
  • Zuletzt bearbeitet 21.11.2024 05:25:00

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.

  • EPSS 0.43%
  • Veröffentlicht 15.07.2020 18:15:36
  • Zuletzt bearbeitet 21.11.2024 05:24:59

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.

  • EPSS 0.3%
  • Veröffentlicht 25.03.2020 17:15:15
  • Zuletzt bearbeitet 21.11.2024 05:24:49

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to defin...

  • EPSS 0.43%
  • Veröffentlicht 25.03.2020 17:15:15
  • Zuletzt bearbeitet 21.11.2024 05:24:49

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.