Jenkins Project Jenkins vulnerabilities

75 known vulnerabilities affecting jenkins_project/jenkins.

Total CVEs
75
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH18MEDIUM46

Vulnerabilities

Page 3 of 4
CVE-2021-21606MEDIUMCVSS 4.3≥ 2.242, < unspecified≥ unspecified, ≤ 2.2742021-01-13
CVE-2021-21606 [MEDIUM] CWE-20 CVE-2021-21606: Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fin Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.
cvelistv5nvd
CVE-2020-2230MEDIUMCVSS 5.4PoC≥ unspecified, ≤ 2.2512020-08-12
CVE-2020-2230 [MEDIUM] CWE-79 CVE-2020-2230: Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy descr Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
cvelistv5nvd
CVE-2020-2229MEDIUMCVSS 5.4PoC≥ unspecified, ≤ 2.2512020-08-12
CVE-2020-2229 [MEDIUM] CWE-79 CVE-2020-2229: Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
cvelistv5nvd
CVE-2020-2231MEDIUMCVSS 5.4PoC≥ unspecified, ≤ 2.2512020-08-12
CVE-2020-2231 [MEDIUM] CWE-79 CVE-2020-2231: Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host st Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
cvelistv5nvd
CVE-2020-2223MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2442020-07-15
CVE-2020-2223 [MEDIUM] CWE-79 CVE-2020-2223: Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.
cvelistv5nvd
CVE-2020-2220MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2442020-07-15
CVE-2020-2220 [MEDIUM] CWE-79 CVE-2020-2220: Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
cvelistv5nvd
CVE-2020-2221MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2442020-07-15
CVE-2020-2221 [MEDIUM] CWE-79 CVE-2020-2221: Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name s Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.
cvelistv5nvd
CVE-2020-2222MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2442020-07-15
CVE-2020-2222 [MEDIUM] CWE-79 CVE-2020-2222: Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this bu Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.
cvelistv5nvd
CVE-2020-2160HIGHCVSS 8.8≥ unspecified, ≤ 2.227≥ unspecified, ≤ LTS 2.204.52020-03-25
CVE-2020-2160 [HIGH] CVE-2020-2160: Jenkins 2 Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
cvelistv5
CVE-2020-2163MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2272020-03-25
CVE-2020-2163 [MEDIUM] CWE-79 CVE-2020-2163: Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view co Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerability exploitable by users able to control column headers.
cvelistv5nvd
CVE-2020-2161MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2272020-03-25
CVE-2020-2161 [MEDIUM] CWE-79 CVE-2020-2161: Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are sho Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
cvelistv5nvd
CVE-2020-2162MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2272020-03-25
CVE-2020-2162 [MEDIUM] CWE-79 CVE-2020-2162: Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.
cvelistv5nvd
CVE-2012-0785HIGHCVSS 7.5vbefore 1.4472020-02-24
CVE-2012-0785 [HIGH] CWE-400 CVE-2012-0785: Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."
cvelistv5nvd
CVE-2020-2099HIGHCVSS 8.6≥ unspecified, ≤ 2.2132020-01-29
CVE-2020-2099 [HIGH] CWE-330 CVE-2020-2099: Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in th Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.
cvelistv5nvd
CVE-2020-2101MEDIUMCVSS 5.3≥ unspecified, ≤ 2.2182020-01-29
CVE-2020-2101 [MEDIUM] CWE-203 CVE-2020-2101: Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function f Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.
cvelistv5nvd
CVE-2020-2104MEDIUMCVSS 4.3≥ unspecified, ≤ 2.2182020-01-29
CVE-2020-2104 [MEDIUM] CWE-863 CVE-2020-2104: Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.
cvelistv5nvd
CVE-2020-2100MEDIUMCVSS 5.8≥ unspecified, ≤ 2.2182020-01-29
CVE-2020-2100 [MEDIUM] CVE-2020-2100: Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848.
cvelistv5nvd
CVE-2020-2105MEDIUMCVSS 5.4≥ unspecified, ≤ 2.2182020-01-29
CVE-2020-2105 [MEDIUM] CWE-1021 CVE-2020-2105: REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjac REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
cvelistv5nvd
CVE-2020-2102MEDIUMCVSS 5.3≥ unspecified, ≤ 2.2182020-01-29
CVE-2020-2102 [MEDIUM] CWE-203 CVE-2020-2102: Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
cvelistv5nvd
CVE-2020-2103MEDIUMCVSS 5.4PoC≥ unspecified, ≤ 2.2182020-01-29
CVE-2020-2103 [MEDIUM] CWE-200 CVE-2020-2103: Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail ob Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
cvelistv5nvd