Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2021-05-11 CVE-2021-21655 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins P4
A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified Perforce server using attacker-specified username and password.
network
low complexity
jenkins CWE-352
7.1
2021-05-11 CVE-2021-21656 Unspecified vulnerability in Jenkins Xcode Integration
Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins
7.1
2021-04-21 CVE-2021-21647 Unspecified vulnerability in Jenkins Cloudbees CD
Jenkins CloudBees CD Plugin 1.1.21 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Item/Read permission to schedule builds of projects without having Item/Build permission.
network
low complexity
jenkins
4.3
2021-04-21 CVE-2021-21646 Unspecified vulnerability in Jenkins Templating Engine
Jenkins Templating Engine Plugin 2.1 and earlier does not protect its pipeline configurations using Script Security Plugin, allowing attackers with Job/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.
network
low complexity
jenkins
8.8
2021-04-21 CVE-2021-21645 Unspecified vulnerability in Jenkins Config File Provider
Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, attackers with Overall/Read permission to enumerate configuration file IDs.
network
low complexity
jenkins
4.3
2021-04-21 CVE-2021-21644 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Config File Provider
A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attackers to delete configuration files corresponding to an attacker-specified ID.
network
low complexity
jenkins CWE-352
5.4
2021-04-21 CVE-2021-21643 Unspecified vulnerability in Jenkins Config File Provider
Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpoints, allowing attackers with global Job/Configure permission to enumerate system-scoped credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins
6.5
2021-04-21 CVE-2021-21642 XXE vulnerability in Jenkins Config File Provider
Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
8.1
2021-04-07 CVE-2021-21641 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Promoted Builds
A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to to promote builds.
network
low complexity
jenkins CWE-352
4.3
2021-04-07 CVE-2021-21640 Unspecified vulnerability in Jenkins
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not properly check that a newly created view has an allowed name, allowing attackers with View/Create permission to create views with invalid or already-used names.
network
low complexity
jenkins
4.3