Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2018-08-01 CVE-2018-1999026 Server-Side Request Forgery (SSRF) vulnerability in Jenkins Tracetronic Ecu-Test
A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers to have Jenkins send HTTP requests to an attacker-specified host.
network
low complexity
jenkins CWE-918
6.5
2018-08-01 CVE-2018-1999025 Improper Certificate Validation vulnerability in Jenkins Tracetronic Ecu-Test
A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows attackers to impersonate any service that Jenkins connects to.
network
high complexity
jenkins CWE-295
7.4
2018-07-27 CVE-2017-2652 Improper Authentication vulnerability in Jenkins Distributed Fork
It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Overall/Read permission, allowing anyone with that permission to run arbitrary shell commands on all connected nodes.
network
low complexity
jenkins CWE-287
8.8
2018-07-27 CVE-2017-2650 Unspecified vulnerability in Jenkins Pipeline Classpath Step 0.1.0
It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access, as well as users with e.g.
network
high complexity
jenkins
8.5
2018-07-27 CVE-2017-2649 Improper Certificate Validation vulnerability in Jenkins Active Directory
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
network
high complexity
jenkins CWE-295
8.1
2018-07-27 CVE-2017-2648 Improper Certificate Validation vulnerability in Jenkins SSH Slaves
It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.
network
high complexity
jenkins CWE-295
5.6
2018-07-27 CVE-2017-2651 Information Exposure vulnerability in Jenkins Mailer
jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs.
network
high complexity
jenkins CWE-200
3.7
2018-07-23 CVE-2018-1999007 Cross-site Scripting vulnerability in multiple products
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would be executed in another user's browser when that other user views HTTP 404 error pages while Stapler debug mode is enabled.
network
low complexity
jenkins oracle CWE-79
5.4
2018-07-23 CVE-2018-1999006 Information Exposure vulnerability in Jenkins
A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically is the date of the most recent installation/upgrade.
network
low complexity
jenkins CWE-200
4.3
2018-07-23 CVE-2018-1999005 Cross-site Scripting vulnerability in multiple products
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
network
low complexity
jenkins oracle CWE-79
5.4