Vulnerabilities
Vulnerable Software
Jenkins:  Security Vulnerabilities
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override the global `config.xml` file.
CVSS Score
8.0
EPSS Score
0.022
Published
2021-01-13
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.
CVSS Score
4.3
EPSS Score
0.012
Published
2021-01-13
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to request crafted URLs that use all available memory in Jenkins, potentially leading to out of memory errors.
CVSS Score
6.5
EPSS Score
0.014
Published
2021-01-13
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to control button labels.
CVSS Score
5.4
EPSS Score
0.01
Published
2021-01-13
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did have Overall/Read permission.
CVSS Score
5.3
EPSS Score
0.013
Published
2021-01-13
Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.
CVSS Score
9.8
EPSS Score
0.009
Published
2020-12-03
A cross-site request forgery (CSRF) vulnerability in Jenkins Shelve Project Plugin 3.0 and earlier allows attackers to shelve, unshelve, or delete a project.
CVSS Score
8.1
EPSS Score
0.007
Published
2020-12-03
Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVSS Score
7.5
EPSS Score
0.013
Published
2020-12-03
Jenkins SQLPlus Script Runner Plugin 2.0.12 and earlier does not mask a password provided as command line argument in build logs.
CVSS Score
6.5
EPSS Score
0.01
Published
2020-11-04
A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVSS Score
4.3
EPSS Score
0.008
Published
2020-11-04


Contact Us

Shodan ® - All rights reserved