← Browse

Jenkins Project

56 CVEs
CVE IDSeverityProduct / summaryPublished
CVE-2026-84645 HIGH 8.8 Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration … 2026-09-02 CVE-2026-84646 MEDIUM 4.3 Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other… 2026-09-02 CVE-2026-84647 HIGH 8.8 Jenkins — In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and ear… 2026-09-02 CVE-2026-84648 HIGH 8.8 Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metada… 2026-09-02 CVE-2026-84649 HIGH 8.8 Jenkins — In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6… 2026-09-02 CVE-2026-84650 HIGH 8.8 Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserializatio… 2026-09-02 CVE-2026-84651 MEDIUM 6.3 Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent confi… 2026-09-02 CVE-2026-84652 HIGH 7.3 Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is auth… 2026-09-02 CVE-2026-84653 LOW 3.5 Jenkins — Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly … 2026-09-02 CVE-2026-84654 MEDIUM 5.4 Jenkins — In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and ear… 2026-09-02 CVE-2026-84655 MEDIUM 4.3 Jenkins — Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON a… 2026-09-02 CVE-2026-84656 MEDIUM 4.3 Jenkins — A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Re… 2026-09-02 CVE-2026-84657 MEDIUM 4.2 Jenkins — In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel pe… 2026-09-02 CVE-2026-84658 MEDIUM 4.3 Jenkins Script Security Plugin — Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructor` annotation on … 2026-09-02 CVE-2026-84659 MEDIUM 4.3 Jenkins Script Security Plugin — Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission check in the meth… 2026-09-02 CVE-2026-84660 MEDIUM 5.4 Jenkins Pipeline: Build Step Plugin — A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes down… 2026-09-02 CVE-2026-84661 MEDIUM 5.4 Jenkins Pipeline: Build Step Plugin — A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes down… 2026-09-02 CVE-2026-84662 MEDIUM 4.3 Jenkins Ldap Plugin — Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler da… 2026-09-02 CVE-2026-84663 MEDIUM 5.4 Jenkins Pipeline: Groovy Libraries Plugin — A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v5cc6888253… 2026-09-02 CVE-2026-84664 MEDIUM 5.4 Jenkins Gitlab Plugin — Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global GitLab connection configuration through… 2026-09-02 CVE-2026-84665 HIGH 8 Jenkins Sonarqube Scanner Plugin — Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it crea… 2026-09-02 CVE-2026-84666 MEDIUM 5.4 Jenkins Job Configuration History Plugin — Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's hist… 2026-09-02 CVE-2026-84667 HIGH 7.1 Jenkins Thinbackup Plugin — Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plugin's backup configuration through Stapl… 2026-09-02 CVE-2026-84668 HIGH 8.8 Jenkins Saml Plugin — Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata f… 2026-09-02 CVE-2026-84669 HIGH 8.8 Jenkins Allure Plugin — A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read per… 2026-09-02 CVE-2026-84670 HIGH 8.8 Jenkins Performance Plugin — Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instanti… 2026-09-02 CVE-2026-84671 HIGH 8.8 Jenkins File Parameter Plugin — Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on t… 2026-09-02 CVE-2026-84672 HIGH 8.8 Jenkins Microsoft Entra Id (Previously Azure Ad) Plugin — Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group perm… 2026-09-02 CVE-2026-84673 HIGH 8.8 Jenkins Customizable Header Plugin — Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance… 2026-09-02 CVE-2026-84674 MEDIUM 5.4 Jenkins Xebialabs Xl Deploy Plugin — Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overal… 2026-09-02 CVE-2026-84675 HIGH 7.4 Jenkins Tics Plugin — OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to contro… 2026-09-02 CVE-2026-84676 MEDIUM 4.3 Jenkins Parameterized Remote Trigger Plugin — Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml file… 2026-09-02 CVE-2026-84677 MEDIUM 5.4 Jenkins Update Center2 — Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, … 2026-09-02 CVE-2026-70426 CRITICAL 9 Jenkins — In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earl… 2026-08-05 CVE-2026-70427 MEDIUM 4.3 Jenkins — Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empt… 2026-08-05 CVE-2026-70428 MEDIUM 4.3 Jenkins — Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal … 2026-08-05 CVE-2026-70429 HIGH 8.1 Jenkins — Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names in… 2026-08-05 CVE-2026-70430 LOW 2.7 Jenkins — Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instanti… 2026-08-05 CVE-2026-70431 HIGH 8.8 Jenkins Multijob Plugin — Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integra… 2026-08-05 CVE-2026-70432 HIGH 8.8 Jenkins Multijob Plugin — A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier a… 2026-08-05 CVE-2026-70433 MEDIUM 4.3 Jenkins Hcl Appscan Plugin — Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read pe… 2026-08-05 CVE-2026-70434 MEDIUM 4.2 Jenkins Scm Manager Plugin — A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows atta… 2026-08-05 CVE-2026-70435 MEDIUM 4.2 Jenkins Scm Manager Plugin — A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read… 2026-08-05 CVE-2026-70436 MEDIUM 4.3 Jenkins External Workspace Manager Plugin — Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and ear… 2026-08-05 CVE-2026-70437 LOW 3.7 Jenkins Webhook Secret Credentials Provider Plugin — Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time … 2026-08-05 CVE-2026-70438 MEDIUM 4.3 Jenkins Parameterized Remote Trigger Plugin — A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers w… 2026-08-05 CVE-2026-70439 MEDIUM 6.5 Jenkins Xml Job To Job Dsl Plugin — Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers la… 2026-08-05 CVE-2026-70440 MEDIUM 5.4 Jenkins Qualys Container Scanning Connector Plugin — Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field v… 2026-08-05 CVE-2026-70441 MEDIUM 5.4 Jenkins Summary Display Plugin — Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build … 2026-08-05 CVE-2026-70442 MEDIUM 4.3 Jenkins Google Chat Notification Plugin — Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context fo… 2026-08-05 CVE-2026-70443 MEDIUM 4.3 Jenkins Horreum Plugin — Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credent… 2026-08-05 CVE-2026-70444 MEDIUM 4.3 Jenkins Violation Comments To Gitlab Plugin — A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers … 2026-08-05 CVE-2026-70445 MEDIUM 4.3 Jenkins Sauce Ondemand Plugin — Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read… 2026-08-05 CVE-2026-70446 MEDIUM 4.3 Jenkins Codesonar Plugin — Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read perm… 2026-08-05 CVE-2026-70447 MEDIUM 4.3 Jenkins Aws Codebuild Plugin — Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read p… 2026-08-05 CVE-2026-70448 HIGH 7.1 Jenkins Ivy Report Plugin — Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XX… 2026-08-05