Show filters
288 Total Results
Displaying 91-100 of 288
Sort by:
Attacker Value
Unknown
CVE-2021-21670
Disclosure Date: June 30, 2021 (last updated October 26, 2023)
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.
0
Attacker Value
Unknown
CVE-2021-21671
Disclosure Date: June 30, 2021 (last updated October 26, 2023)
Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.
0
Attacker Value
Unknown
CVE-2021-21639
Disclosure Date: April 07, 2021 (last updated October 26, 2023)
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not validate the type of object created after loading the data submitted to the `config.xml` REST API endpoint of a node, allowing attackers with Computer/Configure permission to replace a node with one of a different type.
0
Attacker Value
Unknown
CVE-2021-21640
Disclosure Date: April 07, 2021 (last updated October 26, 2023)
Jenkins 2.286 and earlier, LTS 2.277.1 and earlier does not properly check that a newly created view has an allowed name, allowing attackers with View/Create permission to create views with invalid or already-used names.
0
Attacker Value
Unknown
CVE-2021-28165
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
0
Attacker Value
Unknown
CVE-2021-21615
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifacts due to a time-of-check to time-of-use (TOCTOU) race condition.
0
Attacker Value
Unknown
CVE-2021-21608
Disclosure Date: January 13, 2021 (last updated February 22, 2025)
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to control button labels.
0
Attacker Value
Unknown
CVE-2021-21611
Disclosure Date: January 13, 2021 (last updated February 22, 2025)
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names or IDs of item types.
0
Attacker Value
Unknown
CVE-2021-21603
Disclosure Date: January 13, 2021 (last updated February 22, 2025)
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2021-21602
Disclosure Date: January 13, 2021 (last updated February 22, 2025)
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by following symlinks.
0