Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2018-03-13 CVE-2018-1000105 Incorrect Authorization vulnerability in Jenkins Gerrit Trigger
An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to retrieve some configuration information about Gerrit in Jenkins.
network
low complexity
jenkins CWE-863
4.3
2018-03-13 CVE-2018-1000104 Insufficiently Protected Credentials vulnerability in Jenkins Coverity
A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with local file system access or control of a Jenkins administrator's web browser (e.g.
local
low complexity
jenkins CWE-522
7.8
2018-02-20 CVE-2018-6356 Path Traversal vulnerability in multiple products
Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files.
network
low complexity
jenkins oracle CWE-22
6.5
2018-02-16 CVE-2018-1000068 Information Exposure vulnerability in multiple products
An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on a case-insensitive file system.
network
low complexity
jenkins oracle CWE-200
5.3
2018-02-16 CVE-2018-1000067 Server-Side Request Forgery (SSRF) vulnerability in multiple products
An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.
network
low complexity
jenkins oracle CWE-918
5.3
2018-02-09 CVE-2018-1000058 Deserialization of Untrusted Data vulnerability in Jenkins Pipeline Supporting Apis 2.15/2.16/2.17
Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to Java deserialization like readResolve implemented in Pipeline scripts were not subject to sandbox protection, and could therefore execute arbitrary code.
network
low complexity
jenkins CWE-502
8.8
2018-02-09 CVE-2018-1000057 Insufficiently Protected Credentials vulnerability in Jenkins Credentials Binding
Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs.
network
low complexity
jenkins CWE-522
4.3
2018-02-09 CVE-2018-1000056 Server-Side Request Forgery (SSRF) vulnerability in Jenkins Junit
Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
network
low complexity
jenkins CWE-918
8.3
2018-02-09 CVE-2018-1000055 Server-Side Request Forgery (SSRF) vulnerability in Jenkins Android Lint
Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
network
low complexity
jenkins CWE-918
8.3
2018-02-09 CVE-2018-1000054 Server-Side Request Forgery (SSRF) vulnerability in Jenkins CCM
Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
network
low complexity
jenkins CWE-918
8.3