Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2019-11-21 CVE-2019-16539 Improper Preservation of Permissions vulnerability in Jenkins Support Core
A missing permission check in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete support bundles.
network
low complexity
jenkins CWE-281
6.5
2019-11-21 CVE-2019-16538 Incorrect Authorization vulnerability in Jenkins Script Security
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute arbitrary code in sandboxed scripts.
network
low complexity
jenkins CWE-863
8.8
2019-11-18 CVE-2012-4441 Cross-site Scripting vulnerability in Jenkins
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.
network
low complexity
jenkins CWE-79
6.1
2019-11-18 CVE-2012-4440 Cross-site Scripting vulnerability in Jenkins
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.
network
low complexity
jenkins CWE-79
6.1
2019-11-18 CVE-2012-4439 Cross-site Scripting vulnerability in Jenkins
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.
network
low complexity
jenkins CWE-79
6.1
2019-11-18 CVE-2012-4438 Improper Input Validation vulnerability in Jenkins
Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers with read access and HTTP access to Jenkins master to insert data and execute arbitrary code.
network
low complexity
jenkins CWE-20
8.8
2019-10-23 CVE-2019-10476 Insufficiently Protected Credentials vulnerability in Jenkins Zulip
Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
local
low complexity
jenkins CWE-522
7.8
2019-10-23 CVE-2019-10475 Cross-site Scripting vulnerability in Jenkins Build-Metrics
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.
network
low complexity
jenkins CWE-79
6.1
2019-10-23 CVE-2019-10474 Incorrect Default Permissions vulnerability in Jenkins Global Post Script
A missing permission check in Jenkins Global Post Script Plugin in allowed users with Overall/Read access to list the scripts available to the plugin stored on the Jenkins master file system.
network
low complexity
jenkins CWE-276
4.3
2019-10-23 CVE-2019-10473 Incorrect Default Permissions vulnerability in Jenkins Libvirt Slaves
A missing permission check in Jenkins Libvirt Slaves Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
network
low complexity
jenkins CWE-276
4.3