|
CVE-2026-84652
|
High
|
2026-09-02
|
No fix identified
|
No public exploit
|
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the "remember me" cookie, grants the attacker access to Jenkins as that user.
|
|
CVE-2026-84651
|
Medium
|
2026-09-02
|
No fix identified
|
No public exploit
|
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers with Agent/Configure permission on one agent to take over a different agent, gaining control of its configuration and obtaining access to its inbound agent secret and environment variables.
|
|
CVE-2026-84650
|
High
|
2026-09-02
|
Protected by RASP
|
No public exploit
|
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.
|
|
CVE-2026-84648
|
High
|
2026-09-02
|
No fix identified
|
No public exploit
|
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.
|
|
CVE-2026-84646
|
Medium
|
2026-09-02
|
Protected by RASP
|
No public exploit
|
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.
|
|
CVE-2026-84645
|
High
|
2026-09-02
|
No fix identified
|
No public exploit
|
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution.
|
|
CVE-2026-70430
|
Low
|
2026-08-05
|
No fix identified
|
No public exploit
|
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration, including those intended for configuration only by administrators.
|
|
CVE-2026-70429
|
High
|
2026-08-05
|
No fix identified
|
No public exploit
|
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted their permissions in some circumstances.
|
|
CVE-2026-70428
|
Medium
|
2026-08-05
|
Protected by RASP
|
No public exploit
|
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.
|
|
CVE-2026-70427
|
Medium
|
2026-08-05
|
No fix identified
|
No public exploit
|
Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write files to arbitrary locations on the file system, restricted only by file system access permissions of the user running Jenkins.
|
|
CVE-2026-57307
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
|
|
CVE-2026-57306
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
|
|
CVE-2026-57305
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified username and password.
|
|
CVE-2026-57304
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username and password.
|
|
CVE-2026-57303
|
High
|
2026-06-24
|
Protected by RASP
|
No public exploit
|
Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.
|
|
CVE-2026-57302
|
Medium
|
2026-06-24
|
Not applicable
|
No public exploit
|
Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Extended Read permission or access to the Jenkins controller file system.
|
|
CVE-2026-57301
|
High
|
2026-06-24
|
No fix identified
|
No public exploit
|
Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
|
|
CVE-2026-57300
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.
|
|
CVE-2026-57299
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.
|
|
CVE-2026-57297
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key.
|
|
CVE-2026-57295
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.
|
|
CVE-2026-57294
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.
|
|
CVE-2026-57290
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier allows attackers to overwrite the global job priority configuration.
|
|
CVE-2026-57289
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token.
|
|
CVE-2026-57288
|
Low
|
2026-06-24
|
No fix identified
|
No public exploit
|
Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries and to authenticate as a matching user whose password they know without knowing their exact user name.
|
|
CVE-2026-57287
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers with Extended Read permission to view encrypted secret values that would otherwise be redacted.
|
|
CVE-2026-57286
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revision metadata.
|
|
CVE-2026-57285
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configuration.
|
|
CVE-2026-57284
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps.
|
|
CVE-2026-57283
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline Snippet Generator.
|
|
CVE-2026-57282
|
Medium
|
2026-06-24
|
No fix identified
|
No public exploit
|
Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent.
|
|
CVE-2026-57281
|
High
|
2026-06-24
|
No exploit published
|
No public exploit
|
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.
|
|
CVE-2026-57280
|
High
|
2026-06-24
|
No fix identified
|
No public exploit
|
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.
|
|
CVE-2026-53442
|
Medium
|
2026-06-10
|
No exploit published
|
No public exploit
|
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.
|
|
CVE-2026-53441
|
Medium
|
2026-06-10
|
No exploit published
|
No public exploit
|
Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
|
|
CVE-2026-53440
|
Medium
|
2026-06-10
|
No exploit published
|
No public exploit
|
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.
|
|
CVE-2026-53439
|
Medium
|
2026-06-10
|
No exploit published
|
No public exploit
|
Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".
|
|
CVE-2026-53438
|
Medium
|
2026-06-10
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel queue items they do not have permission to view.
|
|
CVE-2026-53437
|
High
|
2026-06-10
|
No exploit published
|
No public exploit
|
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks.
|
|
CVE-2026-53436
|
Medium
|
2026-06-10
|
No exploit published
|
No public exploit
|
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), allowing attackers to perform phishing attacks.
|
|
CVE-2026-53435
|
High
|
2026-06-10
|
Protected by RASP
|
Proof of concept only
|
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards.
This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.
|
|
CVE-2026-9674
|
Medium
|
2026-05-27
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds.
|
|
CVE-2026-48927
|
Medium
|
2026-05-27
|
No exploit published
|
No public exploit
|
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.
|
|
CVE-2026-48926
|
Medium
|
2026-05-27
|
No exploit published
|
No public exploit
|
Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
|
|
CVE-2026-48924
|
Medium
|
2026-05-27
|
No exploit published
|
No public exploit
|
Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
|
|
CVE-2026-48923
|
Medium
|
2026-05-27
|
No exploit published
|
No public exploit
|
Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect to an attacker-specified URL.
|
|
CVE-2026-48922
|
High
|
2026-05-27
|
Protected by RASP
|
No public exploit
|
Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.
|
|
CVE-2026-48921
|
High
|
2026-05-27
|
No exploit published
|
No public exploit
|
Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.
|
|
CVE-2026-48920
|
High
|
2026-05-27
|
No exploit published
|
No public exploit
|
Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.
|
|
CVE-2026-48919
|
Medium
|
2026-05-27
|
Protected by RASP
|
No public exploit
|
Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.
|
|
CVE-2026-48918
|
Medium
|
2026-05-27
|
No exploit published
|
No public exploit
|
Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.
|
|
CVE-2026-48917
|
Medium
|
2026-05-27
|
Protected by RASP
|
No public exploit
|
Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.
|
|
CVE-2026-48916
|
Medium
|
2026-05-27
|
No exploit published
|
No public exploit
|
Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.
|
|
CVE-2026-42525
|
Medium
|
2026-04-29
|
No exploit published
|
No public exploit
|
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
|
|
CVE-2026-42524
|
High
|
2026-04-29
|
No exploit published
|
No public exploit
|
Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
|
|
CVE-2026-42523
|
Critical
|
2026-04-29
|
No exploit published
|
No public exploit
|
Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.
|
|
CVE-2026-42522
|
Medium
|
2026-04-29
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.
|
|
CVE-2026-42521
|
Medium
|
2026-04-29
|
Protected by RASP
|
No public exploit
|
Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated, allowing attackers with Item/Configure permission to instantiate arbitrary types, which may lead to information disclosure or other impacts depending on the classes available on the classpath.
|
|
CVE-2026-42520
|
High
|
2026-04-29
|
No exploit published
|
No public exploit
|
Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.
|
|
CVE-2026-42519
|
Medium
|
2026-04-29
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.
|
|
CVE-2026-33004
|
Medium
|
2026-03-18
|
No exploit published
|
No public exploit
|
Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
|
|
CVE-2026-33003
|
Medium
|
2026-03-18
|
No exploit published
|
No public exploit
|
Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
|
|
CVE-2026-33002
|
High
|
2026-03-18
|
No exploit published
|
No public exploit
|
Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation.
|
|
CVE-2026-33001
|
High
|
2026-03-18
|
Protected by RASP
|
No public exploit
|
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins.
This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.
|
|
CVE-2026-27100
|
Medium
|
2026-02-18
|
No exploit published
|
No public exploit
|
Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about the existence of jobs, the existence of builds, and if a specified build exists, its display name.
|
|
CVE-2026-27099
|
High
|
2026-02-18
|
No exploit published
|
No public exploit
|
Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.
|
|
CVE-2025-67643
|
Medium
|
2025-12-10
|
No exploit published
|
No public exploit
|
Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to Jira, allowing attackers with Item/Configure permission to retrieve files present on the Jenkins controller workspace directory.
|
|
CVE-2025-67642
|
Medium
|
2025-12-10
|
No exploit published
|
No public exploit
|
Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Vault credentials they are not entitled to.
|
|
CVE-2025-67641
|
High
|
2025-12-10
|
No exploit published
|
No public exploit
|
Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the configured coverage results ID when creating coverage results, only when submitting the job configuration through the UI, allowing attackers with Item/Configure permission to use a `javascript:` scheme URL as identifier by configuring the job through the REST API, resulting in a stored cross-site scripting (XSS) vulnerability.
|
|
CVE-2025-67640
|
Medium
|
2025-12-10
|
No exploit published
|
No public exploit
|
Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS commands.
|
|
CVE-2025-67639
|
Low
|
2025-12-10
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account.
|
|
CVE-2025-67638
|
Medium
|
2025-12-10
|
No exploit published
|
No public exploit
|
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
|
|
CVE-2025-67637
|
Medium
|
2025-12-10
|
No exploit published
|
No public exploit
|
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
|
|
CVE-2025-67636
|
Medium
|
2025-12-10
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.
|
|
CVE-2025-67635
|
High
|
2025-12-10
|
No exploit published
|
No public exploit
|
Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.
|
|
CVE-2025-64150
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
|
|
CVE-2025-64149
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
|
|
CVE-2025-64148
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
|
|
CVE-2025-64147
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
|
|
CVE-2025-64146
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.
|
|
CVE-2025-64145
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
Jenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
|
|
CVE-2025-64144
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.
|
|
CVE-2025-64143
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.
|
|
CVE-2025-64142
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
|
|
CVE-2025-64141
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
|
|
CVE-2025-64140
|
High
|
2025-10-29
|
No exploit published
|
No public exploit
|
Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary shell commands.
|
|
CVE-2025-64139
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
|
|
CVE-2025-64138
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL.
|
|
CVE-2025-64137
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins Themis Plugin 1.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server.
|
|
CVE-2025-64136
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Themis Plugin 1.4.1 and earlier allows attackers to connect to an attacker-specified HTTP server.
|
|
CVE-2025-64135
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value, disabling a protection mechanism of the Java runtime.
|
|
CVE-2025-64134
|
High
|
2025-10-29
|
Protected by RASP
|
No public exploit
|
Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.
|
|
CVE-2025-64133
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and earlier allows attackers to execute sandboxed Groovy code.
|
|
CVE-2025-64132
|
Medium
|
2025-10-29
|
No exploit published
|
No public exploit
|
Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access.
|
|
CVE-2025-64131
|
High
|
2025-10-29
|
No exploit published
|
No public exploit
|
Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.
|
|
CVE-2025-59476
|
Medium
|
2025-09-17
|
No exploit published
|
No public exploit
|
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.
|
|
CVE-2025-59475
|
Medium
|
2025-09-17
|
No exploit published
|
No public exploit
|
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options in this menu (e.g., whether Credentials Plugin is installed).
|
|
CVE-2025-59474
|
Medium
|
2025-09-17
|
Mitigation candidate
|
Working exploit published
|
Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget.
|
|
CVE-2025-58460
|
Medium
|
2025-09-03
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b_92b_cd64 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
|
|
CVE-2025-58459
|
Medium
|
2025-09-03
|
No exploit published
|
No public exploit
|
Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs.
|