Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2023-04-02 CVE-2023-28680 XXE vulnerability in Jenkins Crap4J
Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
7.5
2023-04-02 CVE-2023-28681 XXE vulnerability in Jenkins Visual Studio Code Metrics
Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
8.2
2023-04-02 CVE-2023-28682 XXE vulnerability in Jenkins Performance Publisher
Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
8.2
2023-04-02 CVE-2023-28683 XXE vulnerability in Jenkins Phabricator Differential
Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
8.2
2023-04-02 CVE-2023-28684 XXE vulnerability in Jenkins Remote-Jobs-View 0.0.2/0.0.3
Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
6.5
2023-03-22 CVE-2023-28685 XXE vulnerability in Jenkins Absint A3
Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
7.1
2023-03-10 CVE-2023-27898 Cross-site Scripting vulnerability in Jenkins
Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide plugins to the configured update sites and have this message shown by Jenkins instances.
network
low complexity
jenkins CWE-79
critical
9.6
2023-03-10 CVE-2023-27899 Incorrect Authorization vulnerability in Jenkins
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used, potentially resulting in arbitrary code execution.
local
high complexity
jenkins CWE-863
7.0
2023-03-10 CVE-2023-27900 Allocation of Resources Without Limits or Throttling vulnerability in Jenkins
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in hudson.util.MultipartFormDataParser, allowing attackers to trigger a denial of service.
network
low complexity
jenkins CWE-770
7.5
2023-03-10 CVE-2023-27901 Allocation of Resources Without Limits or Throttling vulnerability in Jenkins
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier uses the Apache Commons FileUpload library without specifying limits for the number of request parts introduced in version 1.5 for CVE-2023-24998 in org.kohsuke.stapler.RequestImpl, allowing attackers to trigger a denial of service.
network
low complexity
jenkins CWE-770
7.5