Show filters
288 Total Results
Displaying 111-120 of 288
Sort by:
Attacker Value
Unknown
CVE-2020-2222
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the job name in the 'Keep this build forever' badge tooltip, resulting in a stored cross-site scripting vulnerability.
0
Attacker Value
Unknown
CVE-2020-2221
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.
0
Attacker Value
Unknown
CVE-2020-2220
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the agent name in the build time trend page, resulting in a stored cross-site scripting vulnerability.
0
Attacker Value
Unknown
CVE-2020-2223
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape correctly the 'href' attribute of links to downstream jobs displayed in the build console page, resulting in a stored cross-site scripting vulnerability.
0
Attacker Value
Unknown
CVE-2020-2160
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier uses different representations of request URL paths, which allows attackers to craft URLs that allow bypassing CSRF protection of any target URL.
0
Attacker Value
Unknown
CVE-2020-2162
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.
0
Attacker Value
Unknown
CVE-2020-2163
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier improperly processes HTML content of list view column headers, resulting in a stored XSS vulnerability exploitable by users able to control column headers.
0
Attacker Value
Unknown
CVE-2020-2161
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
0
Attacker Value
Unknown
CVE-2012-0785
Disclosure Date: February 24, 2020 (last updated February 21, 2025)
Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."
0
Attacker Value
Unknown
CVE-2020-2099
Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to Jenkins, impersonating those agents.
0