Vulnerabilities > Jenkins > High

DATE CVE VULNERABILITY TITLE RISK
2018-02-09 CVE-2018-1000054 Server-Side Request Forgery (SSRF) vulnerability in Jenkins CCM
Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.
network
low complexity
jenkins CWE-918
8.3
2018-01-29 CVE-2017-1000356 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an issue in the Jenkins user database authentication realm: create an account if signup is enabled; or create an account if the victim is an administrator, possibly deleting the existing default admin user in the process and allowing a wide variety of impacts.
network
low complexity
jenkins CWE-352
8.8
2018-01-29 CVE-2017-1000354 Improper Authentication vulnerability in Jenkins
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to a login command which allowed impersonating any Jenkins user.
network
low complexity
jenkins CWE-287
8.8
2018-01-26 CVE-2017-1000403 Incorrect Permission Assignment for Critical Resource vulnerability in Jenkins Speaks! 0.1/0.1.1
Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effectively elevating privileges to Overall/Run Scripts.
network
low complexity
jenkins CWE-732
8.8
2018-01-26 CVE-2017-1000394 Improper Input Validation vulnerability in Jenkins
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092.
network
low complexity
jenkins CWE-20
7.5
2018-01-26 CVE-2017-1000393 OS Command Injection vulnerability in Jenkins
Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could configure a launch method called 'Launch agent via execution of command on master'.
network
low complexity
jenkins CWE-78
8.8
2018-01-26 CVE-2017-1000391 Improper Input Validation vulnerability in Jenkins
Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual user accounts, as well as users appearing in SCM, in directories corresponding to the user ID on disk.
network
low complexity
jenkins CWE-20
7.3
2018-01-26 CVE-2017-1000387 Insufficiently Protected Credentials vulnerability in Jenkins Build-Publisher
Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home directory.
local
low complexity
jenkins CWE-522
7.8
2018-01-24 CVE-2017-1000504 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins
A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initialization.
network
high complexity
jenkins CWE-352
8.1
2018-01-24 CVE-2017-1000503 Race Condition vulnerability in Jenkins
A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of execution of commands during initialization.
network
high complexity
jenkins CWE-362
8.1