Jenkins Project Jenkins vulnerabilities
75 known vulnerabilities affecting jenkins_project/jenkins.
Total CVEs
75
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH18MEDIUM46
Vulnerabilities
Page 3 of 4
CVE-2021-21606MEDIUMCVSS 4.3≥ 2.242, < unspecified≥ unspecified, ≤ 2.2742021-01-13
CVE-2021-21606 [MEDIUM] CWE-20 CVE-2021-21606: Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fin
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.
cvelistv5nvd
CVE-2020-2230MEDIUMCVSS 5.4PoC≥ unspecified, ≤ 2.2512020-08-12
CVE-2020-2230 [MEDIUM] CWE-79 CVE-2020-2230: Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy descr
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
cvelistv5nvd
CVE-2020-2229MEDIUMCVSS 5.4PoC≥ unspecified, ≤ 2.2512020-08-12
CVE-2020-2229 [MEDIUM] CWE-79 CVE-2020-2229: Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
cvelistv5nvd
CVE-2020-2231MEDIUMCVSS 5.4PoC≥ unspecified, ≤ 2.2512020-08-12
CVE-2020-2231 [MEDIUM] CWE-79 CVE-2020-2231: Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host st
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
cvelistv5nvd
CVE-2020-2223MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2442020-07-15
CVE-2020-2223 [MEDIUM] CWE-79 CVE-2020-2223: Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.
cvelistv5nvd
CVE-2020-2220MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2442020-07-15
CVE-2020-2220 [MEDIUM] CWE-79 CVE-2020-2220: Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
cvelistv5nvd
CVE-2020-2221MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2442020-07-15
CVE-2020-2221 [MEDIUM] CWE-79 CVE-2020-2221: Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name s
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.
cvelistv5nvd
CVE-2020-2222MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2442020-07-15
CVE-2020-2222 [MEDIUM] CWE-79 CVE-2020-2222: Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this bu
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.
cvelistv5nvd
CVE-2020-2160HIGHCVSS 8.8≥ unspecified, ≤ 2.227≥ unspecified, ≤ LTS 2.204.52020-03-25
CVE-2020-2160 [HIGH] CVE-2020-2160: Jenkins 2
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
cvelistv5
CVE-2020-2163MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2272020-03-25
CVE-2020-2163 [MEDIUM] CWE-79 CVE-2020-2163: Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view co
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerability exploitable by users able to control column headers.
cvelistv5nvd
CVE-2020-2161MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2272020-03-25
CVE-2020-2161 [MEDIUM] CWE-79 CVE-2020-2161: Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are sho
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
cvelistv5nvd
CVE-2020-2162MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2272020-03-25
CVE-2020-2162 [MEDIUM] CWE-79 CVE-2020-2162: Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.
cvelistv5nvd
CVE-2012-0785HIGHCVSS 7.5vbefore 1.4472020-02-24
CVE-2012-0785 [HIGH] CWE-400 CVE-2012-0785: Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins
Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."
cvelistv5nvd
CVE-2020-2099HIGHCVSS 8.6≥ unspecified, ≤ 2.2132020-01-29
CVE-2020-2099 [HIGH] CWE-330 CVE-2020-2099: Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in th
Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.
cvelistv5nvd
CVE-2020-2101MEDIUMCVSS 5.3≥ unspecified, ≤ 2.2182020-01-29
CVE-2020-2101 [MEDIUM] CWE-203 CVE-2020-2101: Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function f
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.
cvelistv5nvd
CVE-2020-2104MEDIUMCVSS 4.3≥ unspecified, ≤ 2.2182020-01-29
CVE-2020-2104 [MEDIUM] CWE-863 CVE-2020-2104: Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.
cvelistv5nvd
CVE-2020-2100MEDIUMCVSS 5.8≥ unspecified, ≤ 2.2182020-01-29
CVE-2020-2100 [MEDIUM] CVE-2020-2100: Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848.
cvelistv5nvd
CVE-2020-2105MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2182020-01-29
CVE-2020-2105 [MEDIUM] CWE-1021 CVE-2020-2105: REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjac
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
cvelistv5nvd
CVE-2020-2102MEDIUMCVSS 5.3≥ unspecified, ≤ 2.2182020-01-29
CVE-2020-2102 [MEDIUM] CWE-203 CVE-2020-2102: Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
cvelistv5nvd
CVE-2020-2103MEDIUMCVSS 5.4PoC≥ unspecified, ≤ 2.2182020-01-29
CVE-2020-2103 [MEDIUM] CWE-200 CVE-2020-2103: Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail ob
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
cvelistv5nvd