Jenkins Project
56 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-84645
HIGH 8.8
Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration …
2026-09-02
CVE-2026-84646
MEDIUM 4.3
Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other…
2026-09-02
CVE-2026-84647
HIGH 8.8
Jenkins — In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and ear…
2026-09-02
CVE-2026-84648
HIGH 8.8
Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metada…
2026-09-02
CVE-2026-84649
HIGH 8.8
Jenkins — In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6…
2026-09-02
CVE-2026-84650
HIGH 8.8
Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserializatio…
2026-09-02
CVE-2026-84651
MEDIUM 6.3
Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent confi…
2026-09-02
CVE-2026-84652
HIGH 7.3
Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is auth…
2026-09-02
CVE-2026-84653
LOW 3.5
Jenkins — Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly …
2026-09-02
CVE-2026-84654
MEDIUM 5.4
Jenkins — In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and ear…
2026-09-02
CVE-2026-84655
MEDIUM 4.3
Jenkins — Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON a…
2026-09-02
CVE-2026-84656
MEDIUM 4.3
Jenkins — A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Re…
2026-09-02
CVE-2026-84657
MEDIUM 4.2
Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel pe…
2026-09-02
CVE-2026-84658
MEDIUM 4.3
Jenkins Script Security Plugin — Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on …
2026-09-02
CVE-2026-84659
MEDIUM 4.3
Jenkins Script Security Plugin — Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the meth…
2026-09-02
CVE-2026-84660
MEDIUM 5.4
Jenkins Pipeline: Build Step Plugin — A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes down…
2026-09-02
CVE-2026-84661
MEDIUM 5.4
Jenkins Pipeline: Build Step Plugin — A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes down…
2026-09-02
CVE-2026-84662
MEDIUM 4.3
Jenkins Ldap Plugin — Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler da…
2026-09-02
CVE-2026-84663
MEDIUM 5.4
Jenkins Pipeline: Groovy Libraries Plugin — A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc6888253…
2026-09-02
CVE-2026-84664
MEDIUM 5.4
Jenkins Gitlab Plugin — Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through…
2026-09-02
CVE-2026-84665
HIGH 8
Jenkins Sonarqube Scanner Plugin — Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it crea…
2026-09-02
CVE-2026-84666
MEDIUM 5.4
Jenkins Job Configuration History Plugin — Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's hist…
2026-09-02
CVE-2026-84667
HIGH 7.1
Jenkins Thinbackup Plugin — Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapl…
2026-09-02
CVE-2026-84668
HIGH 8.8
Jenkins Saml Plugin — Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata f…
2026-09-02
CVE-2026-84669
HIGH 8.8
Jenkins Allure Plugin — A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read per…
2026-09-02
CVE-2026-84670
HIGH 8.8
Jenkins Performance Plugin — Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instanti…
2026-09-02
CVE-2026-84671
HIGH 8.8
Jenkins File Parameter Plugin — Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on t…
2026-09-02
CVE-2026-84672
HIGH 8.8
Jenkins Microsoft Entra Id (Previously Azure Ad) Plugin — Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group perm…
2026-09-02
CVE-2026-84673
HIGH 8.8
Jenkins Customizable Header Plugin — Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance…
2026-09-02
CVE-2026-84674
MEDIUM 5.4
Jenkins Xebialabs Xl Deploy Plugin — Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overal…
2026-09-02
CVE-2026-84675
HIGH 7.4
Jenkins Tics Plugin — OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to contro…
2026-09-02
CVE-2026-84676
MEDIUM 4.3
Jenkins Parameterized Remote Trigger Plugin — Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml file…
2026-09-02
CVE-2026-84677
MEDIUM 5.4
Jenkins Update Center2 — Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, …
2026-09-02
CVE-2026-70426
CRITICAL 9
Jenkins — In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earl…
2026-08-05
CVE-2026-70427
MEDIUM 4.3
Jenkins — Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empt…
2026-08-05
CVE-2026-70428
MEDIUM 4.3
Jenkins — Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal …
2026-08-05
CVE-2026-70429
HIGH 8.1
Jenkins — Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names in…
2026-08-05
CVE-2026-70430
LOW 2.7
Jenkins — Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instanti…
2026-08-05
CVE-2026-70431
HIGH 8.8
Jenkins Multijob Plugin — Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integra…
2026-08-05
CVE-2026-70432
HIGH 8.8
Jenkins Multijob Plugin — A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier a…
2026-08-05
CVE-2026-70433
MEDIUM 4.3
Jenkins Hcl Appscan Plugin — Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read pe…
2026-08-05
CVE-2026-70434
MEDIUM 4.2
Jenkins Scm Manager Plugin — A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows atta…
2026-08-05
CVE-2026-70435
MEDIUM 4.2
Jenkins Scm Manager Plugin — A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read…
2026-08-05
CVE-2026-70436
MEDIUM 4.3
Jenkins External Workspace Manager Plugin — Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and ear…
2026-08-05
CVE-2026-70437
LOW 3.7
Jenkins Webhook Secret Credentials Provider Plugin — Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time …
2026-08-05
CVE-2026-70438
MEDIUM 4.3
Jenkins Parameterized Remote Trigger Plugin — A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers w…
2026-08-05
CVE-2026-70439
MEDIUM 6.5
Jenkins Xml Job To Job Dsl Plugin — Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers la…
2026-08-05
CVE-2026-70440
MEDIUM 5.4
Jenkins Qualys Container Scanning Connector Plugin — Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field v…
2026-08-05
CVE-2026-70441
MEDIUM 5.4
Jenkins Summary Display Plugin — Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build …
2026-08-05
CVE-2026-70442
MEDIUM 4.3
Jenkins Google Chat Notification Plugin — Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context fo…
2026-08-05
CVE-2026-70443
MEDIUM 4.3
Jenkins Horreum Plugin — Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credent…
2026-08-05
CVE-2026-70444
MEDIUM 4.3
Jenkins Violation Comments To Gitlab Plugin — A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers …
2026-08-05
CVE-2026-70445
MEDIUM 4.3
Jenkins Sauce Ondemand Plugin — Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read…
2026-08-05
CVE-2026-70446
MEDIUM 4.3
Jenkins Codesonar Plugin — Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read perm…
2026-08-05
CVE-2026-70447
MEDIUM 4.3
Jenkins Aws Codebuild Plugin — Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read p…
2026-08-05
CVE-2026-70448
HIGH 7.1
Jenkins Ivy Report Plugin — Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XX…
2026-08-05