Loading HuntDB...

Jenkins project

629 Products 1365 CVEs

CVE Severity Distribution (All Time)

Critical
1
High
15
Medium
25
Low
1

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 15 CVEs

Recent CVEs

View all
CVE-2024-54004 MEDIUM 7 months ago

Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing atta…

CVE-2024-54003 HIGH 7 months ago

Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitab…

CVE-2024-52554 HIGH 7 months, 2 weeks ago

Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not …

CVE-2024-52553 HIGH 7 months, 2 weeks ago

Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.

CVE-2024-52552 HIGH 7 months, 2 weeks ago

Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resulting in…

CVE-2024-52551 HIGH 7 months, 2 weeks ago

Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a bui…

CVE-2024-52550 HIGH 7 months, 2 weeks ago

Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script …

CVE-2024-52549 MEDIUM 7 months, 2 weeks ago

Jenkins Script Security Plugin 1367.vdf2fc45f229c and earlier, except 1365.1367.va_3b_b_89f8a_95b_ and 1362.1364.v4cf2dc5d8776, does not perform a pe…

CVE-2024-47807 HIGH 8 months, 4 weeks ago

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attack…

CVE-2024-47806 HIGH 8 months, 4 weeks ago

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing atta…