Vulnerabilities
Vulnerable Software
Jenkins:  >> Jenkins  >> 2.198  Security Vulnerabilities
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
CVSS Score
5.3
EPSS Score
0.014
Published
2020-01-29
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
CVSS Score
5.4
EPSS Score
0.07
Published
2020-01-29
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.
CVSS Score
4.3
EPSS Score
0.011
Published
2020-01-29
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
CVSS Score
5.4
EPSS Score
0.018
Published
2020-01-29


Contact Us

Shodan ® - All rights reserved