Show filters
288 Total Results
Displaying 111-120 of 288
Sort by:
Attacker Value
Unknown

CVE-2020-2222

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.
Attacker Value
Unknown

CVE-2020-2221

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.
Attacker Value
Unknown

CVE-2020-2220

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
Attacker Value
Unknown

CVE-2020-2223

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.
Attacker Value
Unknown

CVE-2020-2160

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
Attacker Value
Unknown

CVE-2020-2162

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.
Attacker Value
Unknown

CVE-2020-2163

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerability exploitable by users able to control column headers.
Attacker Value
Unknown

CVE-2020-2161

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
Attacker Value
Unknown

CVE-2012-0785

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."
Attacker Value
Unknown

CVE-2020-2099

Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.