Show filters
288 Total Results
Displaying 11-20 of 288
Sort by:
Attacker Value
Unknown
CVE-2025-24400
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event published to RabbitMQ with the legitimate credentials.
0
Attacker Value
Unknown
CVE-2025-24399
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in letter case, potentially gaining administrator access to Jenkins.
0
Attacker Value
Unknown
CVE-2025-24398
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.
0
Attacker Value
Unknown
CVE-2025-24397
Disclosure Date: January 22, 2025 (last updated January 23, 2025)
An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2024-54004
Disclosure Date: November 27, 2024 (last updated December 21, 2024)
Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2024-54003
Disclosure Date: November 27, 2024 (last updated December 21, 2024)
Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Create permission.
0
Attacker Value
Unknown
CVE-2024-52554
Disclosure Date: November 13, 2024 (last updated November 14, 2024)
Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to configure a folder-scoped library override that runs without sandbox protection.
0
Attacker Value
Unknown
CVE-2024-52553
Disclosure Date: November 13, 2024 (last updated November 14, 2024)
Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.
0
Attacker Value
Unknown
CVE-2024-52552
Disclosure Date: November 13, 2024 (last updated November 14, 2024)
Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
0
Attacker Value
Unknown
CVE-2024-52551
Disclosure Date: November 13, 2024 (last updated November 14, 2024)
Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved.
0