Jenkins Jenkins Jenkins CI / CD Server

Do you want an email whenever new security vulnerabilities are reported in any Jenkins product?

Products by Jenkins Sorted by Most Security Vulnerabilities since 2018

Jenkins108 vulnerabilities
Continuous Integration Engine

Jenkins Pipeline27 vulnerabilities

Jenkins Script Security20 vulnerabilities

Jenkins Git12 vulnerabilities

Jenkins Blue Ocean8 vulnerabilities

Jenkins Active Directory7 vulnerabilities

Jenkins Openshift Deployer7 vulnerabilities

Jenkins Rundeck7 vulnerabilities

Jenkins Amazon Ec26 vulnerabilities

Jenkins Repository Connector6 vulnerabilities

Jenkins Xebialabs Xl Deploy6 vulnerabilities

Jenkins Electricflow6 vulnerabilities

Jenkins Subversion6 vulnerabilities

Jenkins Mercurial6 vulnerabilities

Jenkins Project Inheritance6 vulnerabilities

Jenkins Kubernetes6 vulnerabilities

Jenkins Config File Provider6 vulnerabilities

Jenkins Gerrit Trigger5 vulnerabilities

Jenkins Deployment Dashboard5 vulnerabilities

Jenkins Promoted Builds5 vulnerabilities

Jenkins Publish Over Ssh5 vulnerabilities

Jenkins Credentials Binding5 vulnerabilities

Jenkins Websphere Deployer5 vulnerabilities

Jenkins Chef Sinatra5 vulnerabilities

Jenkins Active Choices4 vulnerabilities

Jenkins Rapiddeploy4 vulnerabilities

Jenkins Requests4 vulnerabilities

Jenkins Matrix Project4 vulnerabilities

Jenkins Support Core4 vulnerabilities

Jenkins P44 vulnerabilities

Jenkins Kubernetes Ci4 vulnerabilities

Jenkins Coverity4 vulnerabilities

Jenkins Proxmox4 vulnerabilities

Jenkins S3 Publisher4 vulnerabilities

Jenkins Hashicorp Vault4 vulnerabilities

Jenkins Gitlab4 vulnerabilities

Jenkins Liquibase Runner4 vulnerabilities

Jenkins Mailer4 vulnerabilities

Jenkins Fortify On Demand4 vulnerabilities

Jenkins Git Parameter4 vulnerabilities

Jenkins Cons3rt4 vulnerabilities

Jenkins Github4 vulnerabilities

Jenkins Ssh3 vulnerabilities

Jenkins Rocketchat Notifier3 vulnerabilities

Jenkins Ansible Tower3 vulnerabilities

Jenkins Libvirt Slaves3 vulnerabilities

Jenkins Soasta Cloudtest3 vulnerabilities

Jenkins Google Login3 vulnerabilities

Jenkins Audit To Database3 vulnerabilities

Jenkins Audit Trail3 vulnerabilities

Jenkins Mac3 vulnerabilities

Jenkins Dotci3 vulnerabilities

Jenkins Kmap3 vulnerabilities

Jenkins Maven3 vulnerabilities

Jenkins Azure Ad3 vulnerabilities

Jenkins Email Extension3 vulnerabilities

Jenkins Azure Vm Agents3 vulnerabilities

Jenkins Beaker Builder3 vulnerabilities

Jenkins Repo3 vulnerabilities

Jenkins Rqm3 vulnerabilities

Jenkins Icescrum3 vulnerabilities

Jenkins Black Duck Hub3 vulnerabilities

Jenkins Scriptler3 vulnerabilities

Jenkins Dbcharts3 vulnerabilities

Jenkins Docker3 vulnerabilities

Jenkins Build Publisher3 vulnerabilities

Jenkins Junit3 vulnerabilities

Jenkins Deployer Framework3 vulnerabilities

Jenkins Dashboard View3 vulnerabilities

Jenkins Easyqa3 vulnerabilities

Jenkins Openstack Heat3 vulnerabilities

Jenkins Nomad3 vulnerabilities

Jenkins Ftp Publisher3 vulnerabilities

Jenkins Jira3 vulnerabilities

Jenkins Code Coverage Api3 vulnerabilities

Jenkins Recipe3 vulnerabilities

Recent Jenkins Security Advisories

Advisory Title Published
Jenkins Security Advisory 2022-09-21 September 21, 2022
Jenkins Security Advisory 2022-08-23 August 23, 2022
Jenkins Security Advisory 2022-07-27 July 27, 2022
Jenkins Security Advisory 2015-10-12 July 7, 2022
Jenkins Security Advisory 2022-06-30 June 30, 2022
Jenkins Security Advisory 2022-06-22 June 23, 2022
Jenkins Security Advisory 2022-05-17 May 17, 2022
Jenkins Security Advisory 2022-04-12 April 12, 2022
Jenkins Security Advisory 2022-03-29 March 29, 2022
Jenkins Security Advisory 2022-03-15 March 15, 2022

@jenkinsci Tweets

RT @OrteliusOs: Get ready for #Hacktoberfest. Learn how to setup a local dev environment and review the dev tools to use. A @CDeliveryFdn…
Mon Oct 03 16:14:51 +0000 2022

RT @CDeliveryFdn: Contribute to CD Foundation projects this #Hacktoberfest! �� It's the perfect time to share your love of open source �� R…
Thu Sep 29 20:47:51 +0000 2022

Small but useful steps to improve a Jenkins plugin are outlined in the new "Improve a plugin" tutorial. Want to lea… https://t.co/yhSco91KMp
Wed Sep 21 20:24:00 +0000 2022

The Jenkins security team has issued a security advisory today for the weekly release of Jenkins core and for Jenki… https://t.co/08i4WaY1Bj
Wed Sep 21 15:39:38 +0000 2022

RT @TechMatrix_Se: 2022年11月2日(水)「Jenkins Day Japan 2022」オンライン開催のご案内 https://t.co/IvZWRzUkCc #Jenkins #TechMatrix https://t.co/PUo7HBnQ1r
Wed Sep 21 12:00:40 +0000 2022

By the Year

In 2022 there have been 321 vulnerabilities in Jenkins with an average score of 6.1 out of ten. Last year Jenkins had 102 security vulnerabilities published. That is, 219 more vulnerabilities have already been reported in 2022 as compared to last year. Last year, the average CVE base score was greater by 0.39

Year Vulnerabilities Average Score
2022 321 6.11
2021 102 6.50
2020 173 6.09
2019 340 6.91
2018 120 6.45

It may take a day or so for new Jenkins vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Jenkins Security Vulnerabilities

A missing permission check in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier

CVE-2022-41246 6.5 - Medium - September 21, 2022

A missing permission check in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

AuthZ

A cross-site request forgery (CSRF) vulnerability in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier

CVE-2022-41245 8.8 - High - September 21, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Session Riding

Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the configured View26 server

CVE-2022-41244 8.1 - High - September 21, 2022

Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections.

Improper Validation of Certificate with Host Mismatch

Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26 server

CVE-2022-41243 8.1 - High - September 21, 2022

Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections.

Improper Validation of Certificate with Host Mismatch

A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier

CVE-2022-41242 5.4 - Medium - September 21, 2022

A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps, and rename lamps.

AuthZ

Jenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multiple HTTP endpoints

CVE-2022-41233 4.3 - Medium - September 21, 2022

Jenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multiple HTTP endpoints, allowing attackers with Item/Read permission to obtain information about build artifacts of a given job, if the optional Run/Artifacts permission is enabled.

AuthZ

A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier

CVE-2022-41232 8 - High - September 21, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers to replace any config.xml file on the Jenkins controller file system with an empty file by providing a crafted file name to an API endpoint.

Session Riding

Jenkins Build-Publisher Plugin 1.22 and earlier

CVE-2022-41231 5.7 - Medium - September 21, 2022

Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenkins controller file system by providing a crafted file name to an API endpoint.

Directory traversal

Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers

CVE-2022-41230 4.3 - Medium - September 21, 2022

Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish builds to, as well as builds pending for publication to those Jenkins servers.

AuthZ

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step

CVE-2022-41229 5.4 - Medium - September 21, 2022

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

XSS

A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier

CVE-2022-41228 8.8 - High - September 21, 2022

A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to connect to an attacker-specified webserver using attacker-specified credentials.

AuthZ

A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier

CVE-2022-41227 8.8 - High - September 21, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials.

Session Riding

Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVE-2022-41226 9.8 - Critical - September 21, 2022

Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

XXE

Jenkins Anchore Container Image S

CVE-2022-41225 5.4 - Medium - September 21, 2022

Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control API responses by Anchore engine.

XSS

Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI

CVE-2022-41224 5.4 - Medium - September 21, 2022

Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.

XSS

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins controller where they

CVE-2022-41247 4.3 - Medium - September 21, 2022

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

Insufficiently Protected Credentials

Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVE-2022-41241 9.1 - Critical - September 21, 2022

Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

XXE

Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide malicious API responses

CVE-2022-41240 5.4 - Medium - September 21, 2022

Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide malicious API responses from Walti.

XSS

Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause

CVE-2022-41239 5.4 - Medium - September 21, 2022

Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.

XSS

A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier

CVE-2022-41238 9.8 - Critical - September 21, 2022

A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.

AuthZ

Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types

CVE-2022-41237 9.8 - Critical - September 21, 2022

Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

Marshaling, Unmarshaling

A cross-site request forgery (CSRF) vulnerability in Jenkins Security Inspector Plugin 117.v6eecc36919c2 and earlier

CVE-2022-41236 8.8 - High - September 21, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Security Inspector Plugin 117.v6eecc36919c2 and earlier allows attackers to replace the generated report stored in a per-session cache and displayed to authorized users at the .../report URL with a report based on attacker-specified report generation options.

Session Riding

Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality

CVE-2022-41235 5.3 - Medium - September 21, 2022

Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins controller file system.

Directory traversal

Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users with Overall/Read permission to trigger jobs

CVE-2022-41234 8.8 - High - September 21, 2022

Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users with Overall/Read permission to trigger jobs that are configured to be triggerable via Rundeck.

AuthZ

Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it

CVE-2022-41255 6.5 - Medium - September 21, 2022

Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

Unprotected Storage of Credentials

Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier

CVE-2022-41254 6.5 - Medium - September 21, 2022

Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

AuthZ

A cross-site request forgery (CSRF) vulnerability in Jenkins CONS3RT Plugin 1.0.0 and earlier

CVE-2022-41253 8.8 - High - September 21, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins CONS3RT Plugin 1.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Session Riding

Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier

CVE-2022-41252 4.3 - Medium - September 21, 2022

Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.

AuthZ

A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier

CVE-2022-41251 4.3 - Medium - September 21, 2022

A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

AuthZ

A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier

CVE-2022-41250 6.5 - Medium - September 21, 2022

A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

AuthZ

A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier

CVE-2022-41249 8.8 - High - September 21, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Session Riding

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form

CVE-2022-41248 5.3 - Medium - September 21, 2022

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for attackers to observe and capture it.

Missing Password Field Masking

Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it

CVE-2022-38665 6.5 - Medium - August 23, 2022

Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

Unprotected Storage of Credentials

Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page

CVE-2022-38664 5.4 - Medium - August 23, 2022

Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure job names.

XSS

Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e

CVE-2022-38663 6.5 - Medium - August 23, 2022

Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePassword`) credentials binding.

Insufficiently Protected Credentials

A cross-site request forgery (CSRF) vulnerability in Jenkins Openstack Heat Plugin 1.5 and earlier

CVE-2022-36911 6.5 - Medium - July 27, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers to connect to an attacker-specified URL.

Session Riding

Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories

CVE-2022-36881 8.1 - High - July 27, 2022

Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-the-middle attacks.

Key Exchange without Entity Authentication

Jenkins Openstack Heat Plugin 1.5 and earlier does not perform permission checks in methods implementing form validation

CVE-2022-36913 4.3 - Medium - July 27, 2022

Jenkins Openstack Heat Plugin 1.5 and earlier does not perform permission checks in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

AuthZ

A missing permission check in Jenkins Google Cloud Backup Plugin 0.6 and earlier

CVE-2022-36917 4.3 - Medium - July 27, 2022

A missing permission check in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers with Overall/Read permission to request a manual backup.

AuthZ

A cross-site request forgery (CSRF) vulnerability in Jenkins Google Cloud Backup Plugin 0.6 and earlier

CVE-2022-36916 8 - High - July 27, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers to request a manual backup.

Session Riding

A missing permission check in Jenkins Openstack Heat Plugin 1.5 and earlier

CVE-2022-36912 4.3 - Medium - July 27, 2022

A missing permission check in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

AuthZ

Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints

CVE-2022-36910 5.4 - Medium - July 27, 2022

Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to reindex the database and to obtain information about jobs otherwise inaccessible to them.

AuthZ

A missing permission check in Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier

CVE-2022-36891 4.3 - Medium - July 27, 2022

A missing permission check in Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier allows attackers with Item/Read permission but without Deploy Now/Deploy permission to read deployment logs.

AuthZ

Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementing form validation

CVE-2022-36890 4.3 - Medium - July 27, 2022

Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementing form validation, allowing attackers with Item/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

Directory traversal

A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier

CVE-2022-36888 6.5 - Medium - July 27, 2022

A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain credentials stored in Vault with attacker-specified path and keys.

AuthZ

A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and earlier

CVE-2022-36887 4.3 - Medium - July 27, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and earlier allows attackers to delete entries from job, agent, and system configuration history, or restore older versions of job, agent, and system configurations.

Session Riding

A cross-site request forgery (CSRF) vulnerability in Jenkins External Monitor Job Type Plugin 191.v363d0d1efdf8 and earlier

CVE-2022-36886 4.3 - Medium - July 27, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins External Monitor Job Type Plugin 191.v363d0d1efdf8 and earlier allows attackers to create runs of an external job.

Session Riding

Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal

CVE-2022-36885 5.3 - Medium - July 27, 2022

Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatures are equal, allowing attackers to use statistical methods to obtain a valid webhook signature.

Observable Timing Discrepancy

A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier

CVE-2022-36921 8.1 - High - July 27, 2022

A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

AuthZ

A cross-site request forgery (CSRF) vulnerability in Jenkins Coverity Plugin 1.11.4 and earlier

CVE-2022-36920 8.8 - High - July 27, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Session Riding

A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier

CVE-2022-36919 4.3 - Medium - July 27, 2022

A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

AuthZ

Jenkins Buckminster Plugin 1.1.1 and earlier does not perform a permission check in a method implementing form validation

CVE-2022-36918 4.3 - Medium - July 27, 2022

Jenkins Buckminster Plugin 1.1.1 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

AuthZ

A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier

CVE-2022-36909 6.5 - Medium - July 27, 2022

A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller file system to an attacker-specified URL.

AuthZ

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier

CVE-2022-36908 6.5 - Medium - July 27, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence of an attacker-specified file path on the Jenkins controller file system and to upload a SSH key file from the Jenkins controller file system to an attacker-specified URL.

Session Riding

A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier

CVE-2022-36907 6.5 - Medium - July 27, 2022

A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.

AuthZ

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier

CVE-2022-36906 6.5 - Medium - July 27, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password.

Session Riding

Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven artifact versions parameters

CVE-2022-36905 5.4 - Medium - July 27, 2022

Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven artifact versions parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

XSS

Jenkins Repository Connector Plugin 2.2.0 and earlier does not perform a permission check in a method implementing form validation

CVE-2022-36904 4.3 - Medium - July 27, 2022

Jenkins Repository Connector Plugin 2.2.0 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

AuthZ

A missing permission check in Jenkins Repository Connector Plugin 2.2.0 and earlier

CVE-2022-36903 4.3 - Medium - July 27, 2022

A missing permission check in Jenkins Repository Connector Plugin 2.2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

AuthZ

Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape several fields of Moded Extended Choice parameters

CVE-2022-36902 5.4 - Medium - July 27, 2022

Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape several fields of Moded Extended Choice parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

XSS

Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they

CVE-2022-36901 6.5 - Medium - July 27, 2022

Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

Exposure of Resource to Wrong Sphere

A missing permission check in Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier

CVE-2022-36898 4.3 - Medium - July 27, 2022

A missing permission check in Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.

AuthZ

A missing permission check in Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier

CVE-2022-36897 4.3 - Medium - July 27, 2022

A missing permission check in Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.

AuthZ

A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier

CVE-2022-36896 6.5 - Medium - July 27, 2022

A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.

AuthZ

A missing permission check in Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier

CVE-2022-36895 4.3 - Medium - July 27, 2022

A missing permission check in Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins.

AuthZ

An arbitrary file write vulnerability in Jenkins CLIF Performance Testing Plugin 64.vc0d66de1dfb_f and earlier

CVE-2022-36894 6.5 - Medium - July 27, 2022

An arbitrary file write vulnerability in Jenkins CLIF Performance Testing Plugin 64.vc0d66de1dfb_f and earlier allows attackers with Overall/Read permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.

Directory traversal

Jenkins rpmsign-plugin Plugin 0.5.0 and earlier does not perform a permission check in a method implementing form validation

CVE-2022-36893 4.3 - Medium - July 27, 2022

Jenkins rpmsign-plugin Plugin 0.5.0 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace contents.

AuthZ

Jenkins rhnpush-plugin Plugin 0.5.1 and earlier does not perform a permission check in a method implementing form validation

CVE-2022-36892 4.3 - Medium - July 27, 2022

Jenkins rhnpush-plugin Plugin 0.5.1 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace contents.

AuthZ

Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment

CVE-2022-36889 8.8 - High - July 27, 2022

Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the selected service.

Directory traversal

The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.

CVE-2022-36884 5.3 - Medium - July 27, 2022

The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git repository.

Information Disclosure

A missing permission check in Jenkins Git Plugin 4.11.3 and earlier

CVE-2022-36883 7.5 - High - July 27, 2022

A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.

AuthZ

A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier

CVE-2022-36882 8.8 - High - July 27, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.

Session Riding

Jenkins Files Found Trigger Plugin 1.5 and earlier does not perform a permission check in a method implementing form validation

CVE-2022-36914 4.3 - Medium - July 27, 2022

Jenkins Files Found Trigger Plugin 1.5 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.

AuthZ

Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page

CVE-2022-36922 6.1 - Medium - July 27, 2022

Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page, resulting in a reflected cross-site scripting (XSS) vulnerability.

XSS

Jenkins Android Signing Plugin 2.2.5 and earlier does not perform a permission check in a method implementing form validation

CVE-2022-36915 4.3 - Medium - July 27, 2022

Jenkins Android Signing Plugin 2.2.5 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to check whether attacker-specified file patterns match workspace contents.

AuthZ

The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances

CVE-2015-5298 6.5 - Medium - July 07, 2022

The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side request modification.

authentification

Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.xml files on the Jenkins controller where they

CVE-2022-34803 4.3 - Medium - June 30, 2022

Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission (config.xml), or access to the Jenkins controller file system.

Unprotected Storage of Credentials

Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they

CVE-2022-34802 4.3 - Medium - June 30, 2022

Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

Unprotected Storage of Credentials

Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form

CVE-2022-34801 4.3 - Medium - June 30, 2022

Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

Cleartext Storage of Sensitive Information in Executable

Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they

CVE-2022-34800 4.3 - Medium - June 30, 2022

Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

Unprotected Storage of Credentials

Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it

CVE-2022-34799 4.3 - Medium - June 30, 2022

Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

Unprotected Storage of Credentials

Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints

CVE-2022-34798 6.5 - Medium - June 30, 2022

Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.

AuthZ

A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier

CVE-2022-34797 4.3 - Medium - June 30, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to connect to an attacker-specified HTTP URL using attacker-specified credentials.

Session Riding

A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier

CVE-2022-34796 4.3 - Medium - June 30, 2022

A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

Insufficiently Protected Credentials

Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard view

CVE-2022-34795 5.4 - Medium - June 30, 2022

Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.

XSS

Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier

CVE-2022-34794 6.5 - Medium - June 30, 2022

Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.

AuthZ

Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVE-2022-34793 8.8 - High - June 30, 2022

Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

XXE

A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier

CVE-2022-34792 8 - High - June 30, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.

Session Riding

Jenkins Validating Email Parameter Plugin 1.10 and earlier does not escape the name and description of its parameter type

CVE-2022-34791 5.4 - Medium - June 30, 2022

Jenkins Validating Email Parameter Plugin 1.10 and earlier does not escape the name and description of its parameter type, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

XSS

Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips

CVE-2022-34790 5.4 - Medium - June 30, 2022

Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

XSS

A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier

CVE-2022-34789 6.5 - Medium - June 30, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix builds.

Session Riding

Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips

CVE-2022-34788 5.4 - Medium - June 30, 2022

Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

XSS

Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips

CVE-2022-34787 5.4 - Medium - June 30, 2022

Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control the reason a queue item is blocked.

XSS

Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step

CVE-2022-34786 5.4 - Medium - June 30, 2022

Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.

XSS

Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints

CVE-2022-34785 4.3 - Medium - June 30, 2022

Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about jobs otherwise inaccessible to them.

AuthZ

Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views

CVE-2022-34784 5.4 - Medium - June 30, 2022

Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Build/Update permission.

XSS

Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions

CVE-2022-34783 5.4 - Medium - June 30, 2022

Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

XSS

An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier

CVE-2022-34782 4.3 - Medium - June 30, 2022

An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests.

AuthZ

Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier

CVE-2022-34781 6.5 - Medium - June 30, 2022

Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

AuthZ

A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier

CVE-2022-34780 6.5 - Medium - June 30, 2022

A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Session Riding

Built by Foundeo Inc., with data from the National Vulnerability Database (NVD), Icons by Icons8. Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.