Show filters
288 Total Results
Displaying 121-130 of 288
Sort by:
Attacker Value
Unknown

CVE-2020-2101

Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier did not use a constant-time comparison function for validating connection secrets, which could potentially allow an attacker to use a timing attack to obtain this secret.
Attacker Value
Unknown

CVE-2020-2104

Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier allowed users with Overall/Read access to view a JVM memory usage chart.
Attacker Value
Unknown

CVE-2020-2102

Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier used a non-constant time comparison function when validating an HMAC.
Attacker Value
Unknown

CVE-2020-2100

Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier was vulnerable to a UDP amplification reflection denial of service attack on port 33848.
Attacker Value
Unknown

CVE-2020-2103

Disclosure Date: January 29, 2020 (last updated February 21, 2025)
Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.
Attacker Value
Unknown

CVE-2020-2105

Disclosure Date: January 29, 2020 (last updated February 21, 2025)
REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.
Attacker Value
Unknown

CVE-2019-16544

Disclosure Date: November 21, 2019 (last updated October 26, 2023)
Jenkins QMetry for JIRA - Test Management Plugin 1.12 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Attacker Value
Unknown

CVE-2019-16545

Disclosure Date: November 21, 2019 (last updated October 26, 2023)
Jenkins QMetry for JIRA - Test Management Plugin transmits credentials in its configuration in plain text as part of job configuration forms, potentially resulting in their exposure.
Attacker Value
Unknown

CVE-2012-4440

Disclosure Date: November 18, 2019 (last updated November 27, 2024)
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.
Attacker Value
Unknown

CVE-2012-4441

Disclosure Date: November 18, 2019 (last updated November 27, 2024)
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.