org.jenkins-ci.main:jenkins-core
Maven249 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.main:jenkins-corepage 3 of 5
- CVE-2017-2604MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.442018-05-15
vulnerable: 2.34 ... 2.43 (10 versions)
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not being consistently protected by permission checks (SECURITY-371).
- CVE-2017-2606MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.442018-05-08
vulnerable: 2.34 ... 2.43 (10 versions)
Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that should not be visible (SECURITY-380). This only affects anonymous users (other users legitimately have …
- CVE-2017-2607MEDIUMCVSS 4.2EG 4.2✓ Fixed in 2.442018-05-21
vulnerable: 2.34 ... 2.43 (10 versions)
jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting vulnerability in console notes (SECURITY-382). Jenkins allows plugins to annotate build logs, adding new content or changing the presentation of existin…
- CVE-2017-2608HIGHCVSS 8.8EG 8.8✓ Fixed in 2.442018-05-15
vulnerable: 2.34 ... 2.43 (10 versions)
Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserialization of various types in javax.imageio in XStream-based APIs (SECURITY-383).
- CVE-2017-2609MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.442018-05-22
vulnerable: 2.34 ... 2.43 (10 versions)
jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autocomplete feature on the search box discloses the names of the views in its suggestions, including t…
- CVE-2017-2610MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.442018-05-15
vulnerable: 2.34 ... 2.43 (10 versions)
jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in search suggestions due to improperly escaping users with less-than and greater-than characters in their names (SECURITY-388).
- CVE-2017-2611MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.442018-05-08
vulnerable: 1.396 ... 2.9 (384 versions)
Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read ac…
- CVE-2017-2612MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.442018-05-15
vulnerable: 2.34 ... 2.43 (10 versions)
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds possibly failing to download a JDK.
- CVE-2017-2613MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.442018-05-15
vulnerable: 2.34 ... 2.43 (10 versions)
jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record was only retained until restart in most cases, administrators' web browsers could be manipulated to create a large numbe…
- CVE-2018-1000067MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.1072018-02-16
vulnerable: 2.100 ... 2.99 (17 versions)
An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.
- CVE-2018-1000068MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.1072018-02-16
vulnerable: 2.100 ... 2.99 (17 versions)
An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessi…
- CVE-2018-1000169MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.1162018-04-16
vulnerable: 2.108 ... 2.115 (8 versions)
An exposure of sensitive information vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in CLICommand.java and ViewOptionHandler.java that allows unauthorized attackers to confirm the existence of agents or views with …
- CVE-2018-1000170MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.107.22018-04-16
vulnerable: 1.396 ... 2.99 (462 versions)
A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name cont…
- CVE-2018-1000192MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.1212018-06-05
vulnerable: 2.108 ... 2.120 (13 versions)
A information exposure vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in AboutJenkins.java, ListPluginsCommand.java that allows users with Overall/Read access to enumerate all installed plugins.
- CVE-2018-1000193MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.1212018-06-05
vulnerable: 2.108 ... 2.120 (13 versions)
A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can t…
- CVE-2018-1000194HIGHCVSS 8.1EG 8.1✓ Fixed in 2.1212018-06-05
vulnerable: 2.108 ... 2.120 (13 versions)
A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-…
- CVE-2018-1000195MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.1212018-06-05
vulnerable: 2.108 ... 2.120 (13 versions)
A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary UR…
- CVE-2018-1000406MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.1462019-01-09
vulnerable: 2.140 ... 2.145 (6 versions)
A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permission to define a file parameter with a fi…
- CVE-2018-1000407MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2.1462019-01-09
vulnerable: 2.140 ... 2.145 (6 versions)
A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbitrary attacker-cont…
- CVE-2018-1000408MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.1462019-01-09
vulnerable: 2.140 ... 2.145 (6 versions)
A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific…
- CVE-2018-1000409MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.1462019-01-09
vulnerable: 2.140 ... 2.145 (6 versions)
A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing session and creating …
- CVE-2018-1000410HIGHCVSS 7.8EG 7.8✓ Fixed in 2.1462019-01-09
vulnerable: 2.140 ... 2.145 (6 versions)
An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/mod…
- CVE-2018-1000861CRITICALCVSS 9.8EG 9.8⚠ KEV✓ Fixed in 2.1542018-12-10
vulnerable: 2.140 ... 2.153 (17 versions)
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on …
- CVE-2018-1000862MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.1542018-12-10
vulnerable: 2.140 ... 2.153 (17 versions)
An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running b…
- CVE-2018-1000863HIGHCVSS 8.2EG 8.2✓ Fixed in 2.1542018-12-10
vulnerable: 2.140 ... 2.153 (17 versions)
A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage for…
- CVE-2018-1000864MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.1542018-12-10
vulnerable: 2.140 ... 2.153 (17 versions)
A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
- CVE-2018-1000997MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.1462019-01-23
vulnerable: 2.140 ... 2.145 (6 versions)
A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/org/kohsuke/stapler/Facet.java, groovy/src/main/java/org/kohsuke/stapler/jelly/groovy/Groov…
- CVE-2018-1999001HIGHCVSS 8.8EG 8.8✓ Fixed in 2.1322018-07-23
vulnerable: 2.122 ... 2.131 (10 versions)
A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from…
- CVE-2018-1999002HIGHCVSS 7.5EG 9.0✓ Fixed in 2.1322018-07-23
vulnerable: 2.122 ... 2.131 (10 versions)
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any …
- CVE-2018-1999003MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.1332018-07-23
vulnerable: 2.122 ... 2.132 (11 versions)
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.
- CVE-2018-1999004MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.1322018-07-23
vulnerable: 2.122 ... 2.131 (10 versions)
A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches.
- CVE-2018-1999005MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.1322018-07-23
vulnerable: 2.122 ... 2.131 (10 versions)
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that woul…
- CVE-2018-1999006MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.1322018-07-23
vulnerable: 2.122 ... 2.131 (10 versions)
A exposure of sensitive information vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Plugin.java that allows attackers to determine the date and time when a plugin HPI/JPI file was last extracted, which typically i…
- CVE-2018-1999007MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.1322018-07-23
vulnerable: 2.122 ... 2.131 (10 versions)
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in J…
- CVE-2018-1999042MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.1382018-08-23
vulnerable: 2.122 ... 2.137 (16 versions)
A vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in XStream2.java that allows attackers to have Jenkins resolve a domain name when deserializing an instance of java.net.URL.
- CVE-2018-1999043HIGHCVSS 7.5EG 7.5✓ Fixed in 2.1382018-08-23
vulnerable: 2.122 ... 2.137 (16 versions)
A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in BasicAuthenticationFilter.java, BasicHeaderApiTokenAuthenticator.java that allows attackers to create ephemeral in-memory user records by attempt…
- CVE-2018-1999044MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.1382018-08-23
vulnerable: 1.396 ... 2.99 (497 versions)
A denial of service vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
- CVE-2018-1999045MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.1382018-08-23
vulnerable: 2.122 ... 2.137 (16 versions)
A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2.java that allows attackers with a valid cookie to remain logged in even if that feature i…
- CVE-2018-1999046MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.1382018-08-23
vulnerable: 2.122 ... 2.137 (16 versions)
A exposure of sensitive information vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in Computer.java that allows attackers With Overall/Read permission to access the connection log for any agent.
- CVE-2018-1999047MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.1382018-08-23
vulnerable: 2.122 ... 2.137 (16 versions)
A improper authorization vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in UpdateCenter.java that allows attackers to cancel a Jenkins restart scheduled through the update center.
- CVE-2018-6356MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.1072018-02-20
vulnerable: 2.100 ... 2.99 (17 versions)
Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files …
- CVE-2019-1003003HIGHCVSS 7.2EG 7.2✓ Fixed in 2.1592019-01-22
vulnerable: 2.151 ... 2.158 (8 versions)
An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft…
- CVE-2019-1003004HIGHCVSS 7.2EG 7.2✓ Fixed in 2.1592019-01-22
vulnerable: 1.396 ... 2.99 (524 versions)
An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration of active HTTP ses…
- CVE-2019-1003049HIGHCVSS 8.1EG 8.1✓ Fixed in 2.1722019-04-10
vulnerable: 2.165 ... 2.171 (7 versions)
Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-100300…
- CVE-2019-1003050MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.1722019-04-10
vulnerable: 2.165 ... 2.171 (7 versions)
The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the a…
- CVE-2019-10352MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.1862019-07-17
vulnerable: 2.177 ... 2.185 (9 versions)
A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name out…
- CVE-2019-10353HIGHCVSS 7.5EG 7.5✓ Fixed in 2.1862019-07-17
vulnerable: 2.177 ... 2.185 (9 versions)
CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obtain them to bypass CSRF protection.
- CVE-2019-10354MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.1862019-07-17
vulnerable: 2.177 ... 2.185 (9 versions)
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
- CVE-2019-10383MEDIUMCVSS 4.8EG 4.8✓ Fixed in 2.1922019-08-28
vulnerable: 2.177 ... 2.191 (17 versions)
A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update cente…
- CVE-2019-10384HIGHCVSS 8.8EG 8.8✓ Fixed in 2.1922019-08-28
vulnerable: 2.177 ... 2.191 (17 versions)
Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.
Check whether org.jenkins-ci.main:jenkins-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.main:jenkins-core CVEs against the assets you own.
Start Free Scan →