Vulnerabilities > Jenkins > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-04-07 CVE-2016-0790 7PK - Security Features vulnerability in multiple products
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.
network
low complexity
jenkins redhat CWE-254
5.3
2016-04-07 CVE-2016-0789 Improper Input Validation vulnerability in multiple products
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
network
low complexity
jenkins redhat CWE-20
6.1
2016-02-03 CVE-2015-7536 Cross-site Scripting vulnerability in Jenkins
Cross-site scripting (XSS) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to workspaces and archived artifacts.
network
low complexity
jenkins CWE-79
5.4