Search CVE reports


Toggle filters

1 – 10 of 131 results


CVE-2023-5072

Medium priority
Needs evaluation

Denial of Service in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.

3 affected packages

jenkins-json, libjettison-java, libjson-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jenkins-json Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libjettison-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libjson-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-2798

Medium priority
Needs evaluation

Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a stack...

2 affected packages

htmlunit, jenkins-htmlunit-core-js

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
htmlunit Not in release Not in release Not in release Not in release Needs evaluation
jenkins-htmlunit-core-js Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2015-5298

Medium priority
Ignored

The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps domain through client-side...

1 affected package

jenkins

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jenkins — — — — —
Show less packages

CVE-2022-20612

Medium priority
Ignored

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers to trigger build of job without parameters when no security realm is set.

1 affected package

jenkins

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jenkins — — Not in release Not in release Not in release
Show less packages

CVE-2021-21640

Medium priority

Not in release

Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not properly check that a newly created view has an allowed name, allowing attackers with View/Create permission to create views with invalid or already-used names.

1 affected package

jenkins

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jenkins — — — Not in release Not in release
Show less packages

CVE-2021-21639

Medium priority

Not in release

Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the `config.xml` REST API endpoint of a node, allowing attackers with...

1 affected package

jenkins

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jenkins — — — Not in release Not in release
Show less packages

CVE-2012-0785

Medium priority
Ignored

Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a...

3 affected packages

jenkins, jenkins-executable-war, jenkins-winstone

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jenkins — — — — —
jenkins-executable-war — — — — —
jenkins-winstone — — — — —
Show less packages

CVE-2015-1811

Medium priority
Ignored

XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via a crafted XML document.

1 affected package

jenkins

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jenkins — — — — —
Show less packages

CVE-2015-1809

Medium priority
Ignored

XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files via an XPath query.

1 affected package

jenkins

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jenkins — — — — —
Show less packages

CVE-2012-4441

Medium priority
Ignored

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.

1 affected package

jenkins

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jenkins — — — — —
Show less packages