Show filters
288 Total Results
Displaying 101-110 of 288
Sort by:
Attacker Value
Unknown

CVE-2021-21607

Disclosure Date: January 13, 2021 (last updated February 22, 2025)
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not limit sizes provided as query parameters to graph-rendering URLs, allowing attackers to request crafted URLs that use all available memory in Jenkins, potentially leading to out of memory errors.
Attacker Value
Unknown

CVE-2021-21610

Disclosure Date: January 13, 2021 (last updated February 22, 2025)
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted preview of markup passed as a query parameter, resulting in a reflected cross-site scripting (XSS) vulnerability if the configured markup formatter does not prohibit unsafe elements (JavaScript) in markup.
Attacker Value
Unknown

CVE-2021-21604

Disclosure Date: January 13, 2021 (last updated February 22, 2025)
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows attackers with permission to create or configure various objects to inject crafted content into Old Data Monitor that results in the instantiation of potentially unsafe objects once discarded by an administrator.
Attacker Value
Unknown

CVE-2021-21606

Disclosure Date: January 13, 2021 (last updated February 22, 2025)
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier improperly validates the format of a provided fingerprint ID when checking for its existence allowing an attacker to check for the existence of XML files with a short path.
Attacker Value
Unknown

CVE-2021-21609

Disclosure Date: January 13, 2021 (last updated February 22, 2025)
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not correctly match requested URLs to the list of always accessible paths, allowing attackers without Overall/Read permission to access some URLs as if they did have Overall/Read permission.
Attacker Value
Unknown

CVE-2021-21605

Disclosure Date: January 13, 2021 (last updated February 22, 2025)
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows users with Agent/Configure permission to choose agent names that cause Jenkins to override the global `config.xml` file.
Attacker Value
Unknown

CVE-2020-2251

Disclosure Date: September 01, 2020 (last updated February 22, 2025)
Jenkins SoapUI Pro Functional Testing Plugin 1.5 and earlier transmits project passwords in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.
Attacker Value
Unknown

CVE-2020-2229

Disclosure Date: August 12, 2020 (last updated February 21, 2025)
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2020-2231

Disclosure Date: August 12, 2020 (last updated February 21, 2025)
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
Attacker Value
Unknown

CVE-2020-2230

Disclosure Date: August 12, 2020 (last updated February 21, 2025)
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.