Vulnerabilities > Jenkins > Jenkins > 2.222.3

DATE CVE VULNERABILITY TITLE RISK
2021-01-13 CVE-2021-21602 Link Following vulnerability in Jenkins
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.
network
low complexity
jenkins CWE-59
6.5
2020-08-12 CVE-2020-2231 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
network
low complexity
jenkins CWE-79
5.4
2020-08-12 CVE-2020-2230 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
network
low complexity
jenkins CWE-79
5.4
2020-08-12 CVE-2020-2229 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
network
low complexity
jenkins CWE-79
5.4
2020-07-15 CVE-2020-2223 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.
network
low complexity
jenkins CWE-79
5.4
2020-07-15 CVE-2020-2222 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.
network
low complexity
jenkins CWE-79
5.4
2020-07-15 CVE-2020-2221 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.
network
low complexity
jenkins CWE-79
5.4
2020-07-15 CVE-2020-2220 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
network
low complexity
jenkins CWE-79
5.4