cbcvebase.

Jenkins Pipeline vulnerabilities

40 known vulnerabilities affecting jenkins/pipeline.

Total CVEs
40
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH19MEDIUM18

Vulnerabilities

Page 2 of 2
CVE-2022-28155P3HIGHCVSS 8.1≤ 1.32022-03-29
CVE-2022-28155 [HIGH] CWE-611 CVE-2022-28155: Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to preve Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
nvd
CVE-2022-25179P3MEDIUMCVSS 6.5≤ 706.vd43c65dec0132022-02-15
CVE-2022-25179 [MEDIUM] CWE-59 CVE-2022-25179: Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locatio Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading files using the readTrusted step, allowing attackers able to configure Pipelines permission to read arbitrary files on the Jenkins controller file system.
nvd
CVE-2022-25176P3MEDIUMCVSS 6.5≤ 2648.va9433432b33c2022-02-15
CVE-2022-25176 [MEDIUM] CWE-59 CVE-2022-25176: Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations o Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers able to configure Pipelines to read arbitrary files on the Jenkins controller file system.
nvd
CVE-2024-52551P3HIGHCVSS 8.0≤ 2.2214.vb_b_34b_2ea_9b_832024-11-13
CVE-2024-52551 [HIGH] CWE-276 CVE-2024-52551: Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether th Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved.
nvd
CVE-2024-52550P3HIGHCVSS 8.0fixed in 3975.3977.v478dd9e956c3v_groovy2024-11-13
CVE-2024-52550 [HIGH] CWE-354 CVE-2024-52550: Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.
nvd
CVE-2022-25177P3MEDIUMCVSS 6.5≤ 552.vd9cc05b8a2e12022-02-15
CVE-2022-25177 [MEDIUM] CWE-59 CVE-2022-25177: Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic link Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic links to locations outside of the expected Pipeline library when reading files using the libraryResource step, allowing attackers able to configure Pipelines to read arbitrary files on the Jenkins controller file system.
nvd
CVE-2022-25178P3MEDIUMCVSS 6.5≤ 552.vd9cc05b8a2e12022-02-15
CVE-2022-25178 [MEDIUM] CWE-22 CVE-2022-25178: Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier does not restrict the Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier does not restrict the names of resources passed to the libraryResource step, allowing attackers able to configure Pipelines permission to read arbitrary files on the Jenkins controller file system.
nvd
CVE-2022-28157P3MEDIUMCVSS 6.5≤ 1.32022-03-29
CVE-2022-28157 [MEDIUM] CWE-22 CVE-2022-28157: Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permi Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller via FTP to an attacker-specified FTP server.
nvd
CVE-2022-28156P3MEDIUMCVSS 6.5≤ 1.32022-03-29
CVE-2022-28156 [MEDIUM] CWE-22 CVE-2022-28156: Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permi Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to copy arbitrary files and directories from the Jenkins controller to the agent workspace.
nvd
CVE-2022-25184P3MEDIUMCVSS 6.5≤ 2.152022-02-15
CVE-2022-25184 [MEDIUM] CWE-522 CVE-2022-25184: Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipeline script using the Pipeline Snippet Generator, allowing attackers with Item/Read permission to retrieve the default password parameter value from jobs.
nvd
CVE-2022-28158P4MEDIUMCVSS 6.5≤ 1.32022-03-29
CVE-2022-28158 [MEDIUM] CWE-862 CVE-2022-28158: A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attac A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
nvd
CVE-2022-43408P4MEDIUMCVSS 6.5fixed in 2.272022-10-19
CVE-2022-43408 [MEDIUM] CWE-352 CVE-2022-43408: Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' ste Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.
nvd
CVE-2022-29047P4MEDIUMCVSS 5.3fixed in 2.21.3≥ 544.vff04fa68714d, < 566.vd0a_a_3334a_5552022-04-12
CVE-2022-29047 [MEDIUM] CWE-863 CVE-2022-29047: Jenkins Pipeline: Shared Groovy Libraries Plugin 564.ve62a_4eb_b_e039 and earlier, except 2.21.3, al Jenkins Pipeline: Shared Groovy Libraries Plugin 564.ve62a_4eb_b_e039 and earlier, except 2.21.3, allows attackers able to submit pull requests (or equivalent), but not able to commit directly to the configured SCM, to effectively change the Pipeline behavior by changing the definition of a dynamically retrieved library in their pull request, even i
nvd
CVE-2017-1000089P4MEDIUMCVSS 5.3≤ 2.52017-10-05
CVE-2017-1000089 [MEDIUM] CWE-276 CVE-2017-1000089: Builds in Jenkins are associated with an authentication that controls the permissions that the build Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.
nvd
CVE-2022-43409P4MEDIUMCVSS 5.4≤ 838.va_3a_087b_4055b2022-10-19
CVE-2022-43409 [MEDIUM] CWE-79 CVE-2022-43409: Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or prope Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.
nvd
CVE-2023-32977P4MEDIUMCVSS 5.4≤ 1292.v27d8cc3e26022023-05-16
CVE-2023-32977 [MEDIUM] CWE-79 CVE-2023-32977: Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier bu Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set build display names immediately.
nvd
CVE-2026-57284P4MEDIUMCVSS 4.3≤ 4331.v9d06ed4658ff2026-06-24
CVE-2026-57284 [MEDIUM] CWE-470 CVE-2026-57284: Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps.
nvd
CVE-2022-25180P4MEDIUMCVSS 4.3≤ 2648.va9433432b33c2022-02-15
CVE-2022-25180 [MEDIUM] CWE-319 CVE-2022-25180: Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds, allowing attackers with Run/Replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.
nvd
CVE-2019-10357P4MEDIUMCVSS 4.3≤ 2.142019-07-31
CVE-2019-10357 [MEDIUM] CWE-862 CVE-2019-10357: A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allo A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by global libraries.
nvd
CVE-2026-57283P4MEDIUMCVSS 4.3≤ 4331.v9d06ed4658ff2026-06-24
CVE-2026-57283 [MEDIUM] CWE-352 CVE-2026-57283: A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed465 A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline Snippet Generator.
nvd