<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Jenkins (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/jenkins.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/jenkins-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Jenkins (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:36 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-48922 – Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not prope...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48922</guid>
    <pubDate>Wed, 27 May 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48922</strong></p>
  <p>Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48921 – Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48921</guid>
    <pubDate>Wed, 27 May 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48921</strong></p>
  <p>Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48920 – Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48920</guid>
    <pubDate>Wed, 27 May 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48920</strong></p>
  <p>Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42524 – Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42524</guid>
    <pubDate>Wed, 29 Apr 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42524</strong></p>
  <p>Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42523 – Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job UR...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42523</guid>
    <pubDate>Wed, 29 Apr 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42523</strong></p>
  <p>Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42520 – Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42520</guid>
    <pubDate>Wed, 29 Apr 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42520</strong></p>
  <p>Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a jo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33002 – Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33002</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33002</guid>
    <pubDate>Wed, 18 Mar 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33002</strong></p>
  <p>Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-350</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33002">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33001 – Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33001</guid>
    <pubDate>Wed, 18 Mar 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33001</strong></p>
  <p>Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27099 – Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27099</guid>
    <pubDate>Wed, 18 Feb 2026 15:18:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27099</strong></p>
  <p>Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68931 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68931</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68931</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation. This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68704 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68704</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68704</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing attack mitigation. This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68703 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68703</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68703</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived from sha256Sum(passphrase). Two encryption operations with the same password will have the same derived key. This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68702 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68702</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68702</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses padLeft(32, '0') when it  should use padLeft(64, '0') because SHA-256 produces 32 bytes which equates to 64 hex characters. This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68701 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68701</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68701</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses deterministic AES IV derivation from a passphrase. This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68698 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68698</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68698</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Encoding which is vulnerable to Bleichenbacher padding oracle attacks. Modern systems should use OAEP (Optimal Asymmetric Encryption Padding). This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67635 – Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67635</guid>
    <pubDate>Wed, 10 Dec 2025 17:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67635</strong></p>
  <p>Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64140 – Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64140</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64140</strong></p>
  <p>Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary shell commands.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64134 – Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64134</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64134</strong></p>
  <p>Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64131 – Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64131</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64131</strong></p>
  <p>Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34212 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34212</guid>
    <pubDate>Mon, 29 Sep 2025 21:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34212</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.843 and Application prior to version 20.0.1923 (VA/SaaS deployments) possess CI/CD weaknesses: the build pulls an unverified third-party image, downloads the VirtualBox Extension Pack over plain HTTP without signature validation, and grants the jenkins account NOPASSWD for mount/umount. Together these allow supply c…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53652 – Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53652</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53652</strong></p>
  <p>Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53652">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53650 – Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not prope...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53650</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53650</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53650</strong></p>
  <p>Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to the build log.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53650">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5806 – Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5806</guid>
    <pubDate>Fri, 06 Jun 2025 14:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5806</strong></p>
  <p>Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-47889 – In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47889</guid>
    <pubDate>Wed, 14 May 2025 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-47889</strong></p>
  <p>In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47885 – Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47885</guid>
    <pubDate>Wed, 14 May 2025 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47885</strong></p>
  <p>Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Jenkins Health Advisor server responses.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-47884 – In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the gener...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47884</guid>
    <pubDate>Wed, 14 May 2025 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-47884</strong></p>
  <p>In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a trusted job, potentially gaining unauthorized access to external services.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-32755 – In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32755</guid>
    <pubDate>Thu, 10 Apr 2025 12:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-32755</strong></p>
  <p>In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on Debian, causing all containers based on images of the same version use the same SSH host keys, allowing attackers able to insert themselves into the network path between the SSH client (typically the Jenkins controller) and SSH build agent to impersonate the latter.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-32754 – In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32754</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32754</guid>
    <pubDate>Thu, 10 Apr 2025 12:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-32754</strong></p>
  <p>In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, causing all containers based on images of the same version use the same SSH host keys, allowing attackers able to insert themselves into the network path between the SSH client (typically the Jenkins controller) and SSH build agent to impersonate the latter.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32754">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31722 – In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in fold...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31722</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31722</guid>
    <pubDate>Wed, 02 Apr 2025 15:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31722</strong></p>
  <p>In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31722">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24399 – Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24399</guid>
    <pubDate>Wed, 22 Jan 2025 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24399</strong></p>
  <p>Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that differs only in letter case, potentially gaining administrator access to Jenkins.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24398 – Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24398</guid>
    <pubDate>Wed, 22 Jan 2025 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24398</strong></p>
  <p>Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-54003 – Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, res...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54003</guid>
    <pubDate>Wed, 27 Nov 2024 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-54003</strong></p>
  <p>Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Create permission.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52554 – Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier decl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52554</guid>
    <pubDate>Wed, 13 Nov 2024 21:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52554</strong></p>
  <p>Jenkins Shared Library Version Override Plugin 17.v786074c9fce7 and earlier declares folder-scoped library overrides as trusted, so that they're not executed in the Script Security sandbox, allowing attackers with Item/Configure permission on a folder to configure a folder-scoped library override that runs without sandbox protection.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52553 – Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52553</guid>
    <pubDate>Wed, 13 Nov 2024 21:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52553</strong></p>
  <p>Jenkins OpenId Connect Authentication Plugin 4.418.vccc7061f5b_6d and earlier does not invalidate the previous session on login.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52552 – Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52552</guid>
    <pubDate>Wed, 13 Nov 2024 21:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52552</strong></p>
  <p>Jenkins Authorize Project Plugin 1.7.2 and earlier evaluates a string containing the job name with JavaScript on the Authorization view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52551 – Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52551</guid>
    <pubDate>Wed, 13 Nov 2024 21:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52551</strong></p>
  <p>Jenkins Pipeline: Declarative Plugin 2.2214.vb_b_34b_2ea_9b_83 and earlier does not check whether the main (Jenkinsfile) script used to restart a build from a specific stage is approved, allowing attackers with Item/Build permission to restart a previous build whose (Jenkinsfile) script is no longer approved.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52550 – Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.397...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52550</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52550</guid>
    <pubDate>Wed, 13 Nov 2024 21:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52550</strong></p>
  <p>Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-354</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52550">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47807 – Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47807</guid>
    <pubDate>Wed, 02 Oct 2024 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47807</strong></p>
  <p>Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47806 – Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47806</guid>
    <pubDate>Wed, 02 Oct 2024 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47806</strong></p>
  <p>Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47805 – Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47805</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47805</guid>
    <pubDate>Wed, 02 Oct 2024 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47805</strong></p>
  <p>Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47805">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43044 – Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to rea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43044</guid>
    <pubDate>Wed, 07 Aug 2024 14:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43044</strong></p>
  <p>Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34145 – A sandbox bypass vulnerability involving sandbox-defined classes that shadow spe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34145</guid>
    <pubDate>Thu, 02 May 2024 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34145</strong></p>
  <p>A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-34144 – A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34144</guid>
    <pubDate>Thu, 02 May 2024 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-34144</strong></p>
  <p>A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-2216 – A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-2216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-2216</guid>
    <pubDate>Wed, 06 Mar 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-2216</strong></p>
  <p>A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28160 – Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28160</guid>
    <pubDate>Wed, 06 Mar 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28160</strong></p>
  <p>Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28157 – Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on bui...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28157</guid>
    <pubDate>Wed, 06 Mar 2024 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28157</strong></p>
  <p>Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23904 – Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23904</guid>
    <pubDate>Wed, 24 Jan 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23904</strong></p>
  <p>Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read content from arbitrary files on the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23898 – Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23898</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23898</guid>
    <pubDate>Wed, 24 Jan 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23898</strong></p>
  <p>Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute CLI commands on the Jenkins controller.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23898">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23897 – Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23897</guid>
    <pubDate>Wed, 24 Jan 2024 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23897</strong></p>
  <p>Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50778 – A cross-site request forgery (CSRF) vulnerability in Jenkins PaaSLane Estimate P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50778</guid>
    <pubDate>Wed, 13 Dec 2023 18:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50778</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified token.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50774 – A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50774</guid>
    <pubDate>Wed, 13 Dec 2023 18:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50774</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin 1.02 and earlier allows attackers to delete arbitrary files on the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50768 – A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50768</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50768</guid>
    <pubDate>Wed, 13 Dec 2023 18:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50768</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50768">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50766 – A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50766</guid>
    <pubDate>Wed, 13 Dec 2023 18:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50766</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Platform Plugin 3.18.0-03 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-50764 – Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier does not restrict a file...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50764</guid>
    <pubDate>Wed, 13 Dec 2023 18:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-50764</strong></p>
  <p>Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing attackers with Scriptler/Configure permission to delete arbitrary files on the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49673 – A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49673</guid>
    <pubDate>Wed, 29 Nov 2023 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49673</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-49656 – Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49656</guid>
    <pubDate>Wed, 29 Nov 2023 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-49656</strong></p>
  <p>Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49655 – A cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49655</guid>
    <pubDate>Wed, 29 Nov 2023 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49655</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11.0 and earlier allows attackers to have Jenkins parse an XML file from the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-49654 – Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49654</guid>
    <pubDate>Wed, 29 Nov 2023 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-49654</strong></p>
  <p>Missing permission checks in Jenkins MATLAB Plugin 2.11.0 and earlier allow attackers to have Jenkins parse an XML file from the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46654 – Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locatio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46654</guid>
    <pubDate>Wed, 25 Oct 2023 18:17:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46654</strong></p>
  <p>Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to delete arbitrary files on the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43500 – A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43500</guid>
    <pubDate>Wed, 20 Sep 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43500</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43498 – In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43498</guid>
    <pubDate>Wed, 20 Sep 2023 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43498</strong></p>
  <p>In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using MultipartFormDataParser creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43497 – In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43497</guid>
    <pubDate>Wed, 20 Sep 2023 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43497</strong></p>
  <p>In Jenkins 2.423 and earlier, LTS 2.414.1 and earlier, processing file uploads using the Stapler web framework creates temporary files in the default system temporary directory with the default permissions for newly created files, potentially allowing attackers with access to the Jenkins controller file system to read and write the files before they are used.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43496 – Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43496</guid>
    <pubDate>Wed, 20 Sep 2023 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43496</strong></p>
  <p>Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly created files when installing a plugin from a URL, potentially allowing attackers with access to the system temporary directory to replace the file before it is installed in Jenkins, potentially resulting in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41945 – Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41945</guid>
    <pubDate>Wed, 06 Sep 2023 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41945</strong></p>
  <p>Jenkins Assembla Auth Plugin 1.14 and earlier does not verify that the permissions it grants are enabled, resulting in users with EDIT permissions to be granted Overall/Manage and Overall/SystemRead permissions, even if those permissions are disabled and should not be granted.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41939 – Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions config...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41939</guid>
    <pubDate>Wed, 06 Sep 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41939</strong></p>
  <p>Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41937 – Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41937</guid>
    <pubDate>Wed, 06 Sep 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41937</strong></p>
  <p>Jenkins Bitbucket Push and Pull Request Plugin 2.4.0 through 2.8.3 (both inclusive) trusts values provided in the webhook payload, including certain URLs, and uses configured Bitbucket credentials to connect to those URLs, allowing attackers to capture Bitbucket credentials stored in Jenkins by sending a crafted webhook payload.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41936 – Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41936</guid>
    <pubDate>Wed, 06 Sep 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41936</strong></p>
  <p>Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtain a valid token.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-697</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41935 – Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41935</guid>
    <pubDate>Wed, 06 Sep 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41935</strong></p>
  <p>Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing attackers to use statistical methods to obtain a valid nonce.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-697</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41933 – Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does no...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41933</guid>
    <pubDate>Wed, 06 Sep 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41933</strong></p>
  <p>Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40341 – A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40341</guid>
    <pubDate>Wed, 16 Aug 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40341</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.27.5 and earlier allows attackers to connect to an attacker-specified URL, capturing GitHub credentials associated with an attacker-specified job.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40340 – Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40340</guid>
    <pubDate>Wed, 16 Aug 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40340</strong></p>
  <p>Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in the Npm config file in Pipeline build logs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40339 – Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40339</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40339</guid>
    <pubDate>Wed, 16 Aug 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40339</strong></p>
  <p>Jenkins Config File Provider Plugin 952.va_544a_6234b_46 and earlier does not mask (i.e., replace with asterisks) credentials specified in configuration files when they're written to the build log.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40339">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40336 – A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.84...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40336</guid>
    <pubDate>Wed, 16 Aug 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40336</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy folders.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-3442 – A missing authorization vulnerability exists in versions of the Jenkins Plug-in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3442</guid>
    <pubDate>Wed, 26 Jul 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-3442</strong></p>
  <p>A missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server.  No changes are required on your instances of the Now Platform.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37965 – A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37965</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37965</strong></p>
  <p>A missing permission check in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37964 – A cross-site request forgery (CSRF) vulnerability in Jenkins ElasticBox CI Plugi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37964</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37964</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins ElasticBox CI Plugin 5.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37962 – A cross-site request forgery (CSRF) vulnerability in Jenkins Benchmark Evaluator...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37962</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37962</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers to connect to an attacker-specified URL and to check for the existence of directories, `.csv`, and `.ycsb` files on the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37961 – A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Auth Plugi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37961</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37961</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Auth Plugin 1.14 and earlier allows attackers to trick users into logging in to the attacker's account.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37958 – A cross-site request forgery (CSRF) vulnerability in Jenkins Sumologic Publisher...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37958</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37958</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Sumologic Publisher Plugin 2.2.1 and earlier allows attackers to connect to an attacker-specified URL.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37957 – A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline restFul AP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37957</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37957</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline restFul API Plugin 0.11 and earlier allows attackers to connect to an attacker-specified URL, capturing a newly generated JCLI token.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37949 – A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37949</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37949</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37949</strong></p>
  <p>A missing permission check in Jenkins Orka by MacStadium Plugin 1.33 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37949">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37946 – Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37946</guid>
    <pubDate>Wed, 12 Jul 2023 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37946</strong></p>
  <p>Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-35142 – Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35142</guid>
    <pubDate>Wed, 14 Jun 2023 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-35142</strong></p>
  <p>Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-35141 – In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35141</guid>
    <pubDate>Wed, 14 Jun 2023 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-35141</strong></p>
  <p>In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-33001 – Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33001</guid>
    <pubDate>Tue, 16 May 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-33001</strong></p>
  <p>Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-33000 – Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier doe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33000</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33000</guid>
    <pubDate>Tue, 16 May 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-33000</strong></p>
  <p>Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33000">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32998 – A cross-site request forgery (CSRF) vulnerability in Jenkins AppSpider Plugin 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32998</guid>
    <pubDate>Tue, 16 May 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32998</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins AppSpider Plugin 1.0.15 and earlier allows attackers to connect to an attacker-specified URL and send an HTTP POST request with a JSON payload consisting of attacker-specified credentials.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32997 – Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32997</guid>
    <pubDate>Tue, 16 May 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32997</strong></p>
  <p>Jenkins CAS Plugin 1.6.2 and earlier does not invalidate the previous session on login.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32995 – A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32995</guid>
    <pubDate>Tue, 16 May 2023 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32995</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers to send an HTTP POST request with JSON body containing attacker-specified content, to miniOrange's API for sending emails.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32992 – Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32992</guid>
    <pubDate>Tue, 16 May 2023 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32992</strong></p>
  <p>Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32991 – A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32991</guid>
    <pubDate>Tue, 16 May 2023 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32991</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32989 – A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32989</guid>
    <pubDate>Tue, 16 May 2023 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32989</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32987 – A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32987</guid>
    <pubDate>Tue, 16 May 2023 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32987</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Reverse Proxy Auth Plugin 1.7.4 and earlier allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32986 – Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32986</guid>
    <pubDate>Tue, 16 May 2023 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32986</strong></p>
  <p>Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameters, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32981 – An arbitrary file write vulnerability in Jenkins Pipeline Utility Steps Plugin 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32981</guid>
    <pubDate>Tue, 16 May 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32981</strong></p>
  <p>An arbitrary file write vulnerability in Jenkins Pipeline Utility Steps Plugin 2.15.2 and earlier allows attackers able to provide crafted archives as parameters to create or replace arbitrary files on the agent file system with attacker-specified content.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30525 – A cross-site request forgery (CSRF) vulnerability in Jenkins Report Portal Plugi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30525</guid>
    <pubDate>Wed, 12 Apr 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30525</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Report Portal Plugin 0.5 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified bearer token authentication.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30515 – Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30515</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30515</guid>
    <pubDate>Wed, 12 Apr 2023 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30515</strong></p>
  <p>Jenkins Thycotic DevOps Secrets Vault Plugin 1.0.0 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30515">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30514 – Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30514</guid>
    <pubDate>Wed, 12 Apr 2023 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30514</strong></p>
  <p>Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30513 – Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30513</guid>
    <pubDate>Wed, 12 Apr 2023 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30513</strong></p>
  <p>Jenkins Kubernetes Plugin 3909.v1f2c633e8590 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28683 – Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28683</guid>
    <pubDate>Sun, 02 Apr 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28683</strong></p>
  <p>Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28683">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
