Vulnerabilities
Vulnerable Software
Jenkins:  >> Jenkins  >> 2.19.4  Security Vulnerabilities
A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initialization. There is a very short window of time after startup during which Jenkins may no longer show the 'Please wait while Jenkins is getting ready to work' message but Cross-Site Request Forgery (CSRF) protection may not yet be effective.
CVSS Score
8.1
EPSS Score
0.01
Published
2018-01-24
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
CVSS Score
4.7
EPSS Score
0.012
Published
2017-12-06
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
CVSS Score
9.8
EPSS Score
0.969
Published
2017-01-12


Contact Us

Shodan ® - All rights reserved