Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Total 1647 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-2175 1 Jenkins 1 Fitnesse 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control the XML input files processed by the plugin.
CVE-2020-2229 1 Jenkins 1 Jenkins 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
CVE-2020-2206 1 Jenkins 1 Vncrecorder 2023-11-02 4.3 MEDIUM 6.1 MEDIUM
Jenkins VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.
CVE-2020-2207 1 Jenkins 1 Vncviewer 2023-11-02 4.3 MEDIUM 6.1 MEDIUM
Jenkins VncViewer Plugin 1.7 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.
CVE-2020-2236 1 Jenkins 1 Yet Another Build Visualizer 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission.
CVE-2020-2243 1 Jenkins 1 Cadence Vmanager 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins Cadence vManager Plugin 3.0.4 and earlier does not escape build descriptions in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
CVE-2020-2238 1 Jenkins 1 Git Parameter 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVE-2020-2231 1 Jenkins 1 Jenkins 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
CVE-2020-2230 1 Jenkins 1 Jenkins 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
CVE-2020-2244 1 Jenkins 1 Build Failure Analyzer 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to provide console output for builds used to test build log indications.
CVE-2020-2248 1 Jenkins 1 Jsgames 2023-11-02 4.3 MEDIUM 6.1 MEDIUM
Jenkins JSGames Plugin 0.2 and earlier evaluates part of a URL as code, resulting in a reflected cross-site scripting (XSS) vulnerability.
CVE-2020-2246 1 Jenkins 1 Valgrind 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins Valgrind Plugin 0.28 and earlier does not escape content in Valgrind XML reports, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Valgrind XML report contents.
CVE-2019-10406 1 Jenkins 1 Jenkins 2023-11-02 3.5 LOW 4.8 MEDIUM
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global configuration, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.
CVE-2019-10404 1 Jenkins 1 Jenkins 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the reason why a queue items is blcoked in tooltips, resulting in a stored XSS vulnerability exploitable by users able to control parts of the reason a queue item is blocked, such as label expressions not matching any idle executors.
CVE-2019-10405 1 Jenkins 1 Jenkins 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers exploiting another XSS vulnerability to obtain the HTTP session cookie despite it being marked HttpOnly.
CVE-2019-16562 1 Jenkins 1 Buildgraph-view 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the description of builds shown in its view, resulting in a stored XSS vulnerability exploitable by users able to change build descriptions.
CVE-2020-2137 1 Jenkins 1 Timestamper 2023-11-02 3.5 LOW 4.8 MEDIUM
Jenkins Timestamper Plugin 1.11.1 and earlier does not sanitize HTML formatting of its output, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.
CVE-2020-2106 1 Jenkins 1 Code Coverage Api 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view, resulting in a stored XSS vulnerability exploitable by users able to change job configurations.
CVE-2019-16564 1 Jenkins 1 Pipeline Aggregator View 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to affects view content such as job display name or pipeline stage names.
CVE-2019-16563 1 Jenkins 1 Mission Control 2023-11-02 3.5 LOW 5.4 MEDIUM
Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to change these properties.