Vulnerabilities > Jenkins > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-25 CVE-2017-1000505 Information Exposure vulnerability in Jenkins Script Security
In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coercion feature in Groovy to create new `File` objects from strings.
network
low complexity
jenkins CWE-200
6.5
2018-01-23 CVE-2018-1000015 Missing Authorization vulnerability in Jenkins Pipeline Nodes and Processes
On Jenkins instances with Authorize Project plugin, the authentication associated with a build may lack the Computer/Build permission on some agents.
network
low complexity
jenkins CWE-862
4.8
2017-12-06 CVE-2017-17383 Cross-site Scripting vulnerability in Jenkins
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
network
high complexity
jenkins CWE-79
4.7
2017-11-01 CVE-2017-1000243 Missing Authorization vulnerability in Jenkins Favorite Plugin
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
network
low complexity
jenkins CWE-862
4.3
2017-10-05 CVE-2017-1000113 Information Exposure vulnerability in Jenkins Deploy
The Deploy to container Plugin stored passwords unencrypted as part of its configuration.
local
low complexity
jenkins CWE-200
5.5
2017-10-05 CVE-2017-1000110 Improper Authentication vulnerability in Jenkins Blue Ocean
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins.
network
low complexity
jenkins CWE-287
4.3
2017-10-05 CVE-2017-1000109 Cross-site Scripting vulnerability in Jenkins Owasp Dependency-Check
The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.
network
low complexity
jenkins CWE-79
6.1
2017-10-05 CVE-2017-1000105 Missing Authorization vulnerability in Jenkins Blue Ocean
The optional Run/Artifacts permission can be enabled by setting a Java system property.
network
low complexity
jenkins CWE-862
5.3
2017-10-05 CVE-2017-1000104 Improper Privilege Management vulnerability in Jenkins Config File Provider
The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords.
network
low complexity
jenkins CWE-269
6.5
2017-10-05 CVE-2017-1000103 Cross-site Scripting vulnerability in Jenkins DRY
The custom Details view of the Static Analysis Utilities based DRY Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.
network
low complexity
jenkins CWE-79
5.4