The host is installed with Jenkins LTS through 2.73.2 or Jenkins rolling release through 2.88 and is prone to a persistent cross-site scripting vulnerability. A flaw is present in the application, which fails to properly handle input validation issues. Successful exploitation could allow attackers to cause unspecified impact.
The host is installed with Jenkins LTS through 2.73.2 or Jenkins rolling release through 2.88 and is prone to a privilege escalation vulnerability. A flaw is present in the application, which fails to properly handle input validation issues. Successful exploitation could allow attackers to overwrite unnrelated configuration files.
The host is installed with Jenkins LTS through 2.46.1 or Jenkins rolling release through 2.56 and is prone to a privilege escalation vulnerability. A flaw is present in the application, which fails to properly handle an issue in the user database. Successful exploitation could allow attackers to cause a wide range of impacts.
The host is installed with Jenkins LTS through 2.46.1 or Jenkins rolling release through 2.56 and is prone to a denial of service vulnerability. A flaw is present in the application, which fails to properly handle an issue in instantiation of void. Successful exploitation could allow attackers to cause denial of service.
The host is installed with Jenkins LTS through 2.46.1 or Jenkins rolling release through 2.56 and is prone to a privilege escalation vulnerability. A flaw is present in the application, which fails to properly handle an issue in the login command. Successful exploitation could allow attackers to impersonate any Jenkins user.
The host is installed with Jenkins LTS through 2.46.1 or Jenkins rolling release through 2.56 and is prone to a remote code execution vulnerability. A flaw is present in the application, which fails to properly handle a SignedObject object. Successful exploitation allows remote attackers to carry out unauthenticated remote code execution.
The host is installed with Jenkins LTS before 2.19.3 or Jenkins rolling release before 2.32 and is prone to an arbitrary code execution vulnerability. A flaw is present in the application, which fails to properly handle crafted serialized java object. Successful exploitation could allow attackers to execute arbitrary code via a crafted serialized java object, which triggers an ldap query to a thir ...
The host is installed with Jenkins LTS before 1.651.2 or Jenkins rolling release before 2.3 and is prone to an information disclosure vulnerability. A flaw is present in the application, which fails to properly handle issues in the API URL. Successful exploitation could allow remote authenticated users with extended read permission for the master node to obtain sensitive information about the glob ...
The host is installed with Jenkins LTS before 1.651.2 or Jenkins rolling release before 2.3 and is prone to multiple open redirect vulnerabilities. The flaws are present in the application, which fails to properly handle scheme-relative URLs. Successful exploitation could allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks.
The host is installed with Jenkins LTS before 1.651.2 or Jenkins rolling release before 2.3 and is prone to a denial of service vulnerability. A flaw is present in the application, which fails to properly handle a missing permissions check. Successful exploitation could allow remote authenticated users to trigger updating of update site metadata.