Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2023-07-26 CVE-2023-39153 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Gitlab Authentication
A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Authentication Plugin 1.17.1 and earlier allows attackers to trick users into logging in to the attacker's account.
network
low complexity
jenkins CWE-352
5.4
2023-07-26 CVE-2023-39154 Incorrect Authorization vulnerability in Jenkins Qualys web APP Scanning Connector
Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with global Item/Configure permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-863
6.5
2023-07-26 CVE-2023-39155 Exposure of Resource to Wrong Sphere vulnerability in Jenkins Chef Identity
Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.
network
low complexity
jenkins CWE-668
5.3
2023-07-26 CVE-2023-39156 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Bazaar
A cross-site request forgery (CSRF) vulnerability in Jenkins Bazaar Plugin 1.22 and earlier allows attackers to delete previously created Bazaar SCM tags.
network
low complexity
jenkins CWE-352
5.3
2023-07-12 CVE-2023-37942 XXE vulnerability in Jenkins External Monitor JOB Type
Jenkins External Monitor Job Type Plugin 206.v9a_94ff0b_4a_10 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
6.5
2023-07-12 CVE-2023-37943 Missing Encryption of Sensitive Data vulnerability in Jenkins Active Directory
Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active Directory credentials.
network
high complexity
jenkins CWE-311
5.9
2023-07-12 CVE-2023-37944 Missing Authorization vulnerability in Jenkins Datadog
A missing permission check in Jenkins Datadog Plugin 5.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
6.5
2023-07-12 CVE-2023-37945 Missing Authorization vulnerability in Jenkins Saml Single Sign on 2.1.0/2.2.0/2.3.0
A missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.1.0 through 2.3.0 (both inclusive) allows attackers with Overall/Read permission to download a string representation of the current security realm.
network
low complexity
jenkins CWE-862
4.3
2023-07-12 CVE-2023-37946 Session Fixation vulnerability in Jenkins Openshift Login
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login.
network
low complexity
jenkins CWE-384
8.8
2023-07-12 CVE-2023-37947 Open Redirect vulnerability in Jenkins Openshift Login
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
network
low complexity
jenkins CWE-601
6.1