<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Jenkins</title>
  <link>https://cvedaily.com/pages/tags/jenkins.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/jenkins.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Jenkins</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:36 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-10276 – A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10276</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10276</strong></p>
  <p>A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of the file src/index.ts of the component get_build_status/get_build_log/trigger_build. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the prob…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9674 – A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9674</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9674</guid>
    <pubDate>Wed, 27 May 2026 15:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9674</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9674">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48927 – Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48927</guid>
    <pubDate>Wed, 27 May 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48927</strong></p>
  <p>Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48926 – Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a per...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48926</guid>
    <pubDate>Wed, 27 May 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48926</strong></p>
  <p>Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48925 – A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48925</guid>
    <pubDate>Wed, 27 May 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48925</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to attackers to trigger a build for a pull request.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48924 – Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48924</guid>
    <pubDate>Wed, 27 May 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48924</strong></p>
  <p>Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48923 – Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48923</guid>
    <pubDate>Wed, 27 May 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48923</strong></p>
  <p>Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect to an attacker-specified URL.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48922 – Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not prope...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48922</guid>
    <pubDate>Wed, 27 May 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48922</strong></p>
  <p>Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48921 – Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48921</guid>
    <pubDate>Wed, 27 May 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48921</strong></p>
  <p>Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48920 – Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48920</guid>
    <pubDate>Wed, 27 May 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48920</strong></p>
  <p>Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48919 – Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP ref...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48919</guid>
    <pubDate>Wed, 27 May 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48919</strong></p>
  <p>Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48918 – Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by defau...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48918</guid>
    <pubDate>Wed, 27 May 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48918</strong></p>
  <p>Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48917 – Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48917</guid>
    <pubDate>Wed, 27 May 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48917</strong></p>
  <p>Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-48916 – Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48916</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48916</guid>
    <pubDate>Wed, 27 May 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-48916</strong></p>
  <p>Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48916">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42525 – Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and ea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42525</guid>
    <pubDate>Wed, 29 Apr 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42525</strong></p>
  <p>Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42524 – Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42524</guid>
    <pubDate>Wed, 29 Apr 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42524</strong></p>
  <p>Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42523 – Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job UR...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42523</guid>
    <pubDate>Wed, 29 Apr 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42523</strong></p>
  <p>Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42522 – A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42522</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42522</guid>
    <pubDate>Wed, 29 Apr 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42522</strong></p>
  <p>A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42522">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42521 – Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both incl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42521</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42521</guid>
    <pubDate>Wed, 29 Apr 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42521</strong></p>
  <p>Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated, allowing attackers with Item/Configure permission to instantiate arbitrary types, which may lead to information disclosure or other impact…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42521">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42520 – Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42520</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42520</guid>
    <pubDate>Wed, 29 Apr 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42520</strong></p>
  <p>Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a jo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42520">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42519 – A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42519</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42519</guid>
    <pubDate>Wed, 29 Apr 2026 14:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42519</strong></p>
  <p>A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42519">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33004 – Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33004</guid>
    <pubDate>Wed, 18 Mar 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33004</strong></p>
  <p>Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33003 – Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33003</guid>
    <pubDate>Wed, 18 Mar 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33003</strong></p>
  <p>Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33002 – Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33002</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33002</guid>
    <pubDate>Wed, 18 Mar 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33002</strong></p>
  <p>Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-350</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33002">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33001 – Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33001</guid>
    <pubDate>Wed, 18 Mar 2026 16:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33001</strong></p>
  <p>Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27100 – Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27100</guid>
    <pubDate>Wed, 18 Feb 2026 15:18:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27100</strong></p>
  <p>Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about the existence of jobs, the existence of builds, and if a specified build exists, its display name.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27099 – Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27099</guid>
    <pubDate>Wed, 18 Feb 2026 15:18:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27099</strong></p>
  <p>Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68931 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68931</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68931</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding lacks authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation. This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68925 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68925</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68925</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the code doesn't validate that the JWT header specifies "alg":"RS256". This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68704 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68704</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68704</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.util.Random() which is not cryptographically secure for timing attack mitigation. This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68703 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68703</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68703</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived from sha256Sum(passphrase). Two encryption operations with the same password will have the same derived key. This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68702 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68702</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68702</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses padLeft(32, '0') when it  should use padLeft(64, '0') because SHA-256 produces 32 bytes which equates to 64 hex characters. This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68701 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68701</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68701</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses deterministic AES IV derivation from a passphrase. This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68698 – Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68698</guid>
    <pubDate>Tue, 13 Jan 2026 20:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68698</strong></p>
  <p>Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Encoding which is vulnerable to Bleichenbacher padding oracle attacks. Modern systems should use OAEP (Optimal Asymmetric Encryption Padding). This vulnerability is fixed in 2.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67643 – Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and ea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67643</guid>
    <pubDate>Wed, 10 Dec 2025 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67643</strong></p>
  <p>Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to Jira, allowing attackers with Item/Configure permission to retrieve files present on the Jenkins controller workspace directory.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67642 – Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67642</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67642</guid>
    <pubDate>Wed, 10 Dec 2025 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67642</strong></p>
  <p>Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Vault credentials they are not entitled to.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-282</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67642">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67641 – Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67641</guid>
    <pubDate>Wed, 10 Dec 2025 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67641</strong></p>
  <p>Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the configured coverage results ID when creating coverage results, only when submitting the job configuration through the UI, allowing attackers with Item/Configure permission to use a `javascript:` scheme URL as identifier by configuring the job through the REST API, resulting in a stored cross-site scripting (XSS) vu…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67640 – Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67640</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67640</guid>
    <pubDate>Wed, 10 Dec 2025 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67640</strong></p>
  <p>Jenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a temporary shell script generated by the plugin, allowing attackers able to control the workspace directory name to inject arbitrary OS commands.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67640">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-67639 – A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67639</guid>
    <pubDate>Wed, 10 Dec 2025 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-67639</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into logging in to the attacker's account.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67638 – Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authoriza...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67638</guid>
    <pubDate>Wed, 10 Dec 2025 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67638</strong></p>
  <p>Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67637 – Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67637</guid>
    <pubDate>Wed, 10 Dec 2025 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67637</strong></p>
  <p>Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-67636 – A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67636</guid>
    <pubDate>Wed, 10 Dec 2025 17:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-67636</strong></p>
  <p>A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67635 – Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67635</guid>
    <pubDate>Wed, 10 Dec 2025 17:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67635</strong></p>
  <p>Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13472 – A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13472</guid>
    <pubDate>Wed, 03 Dec 2025 09:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13472</strong></p>
  <p>A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like credential IDs, bzm workspaces and bzm project Ids. Prior to this fix, anyone could see this list as a dropdown on the Jenkins UI.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64150 – A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64150</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64150</strong></p>
  <p>A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64149 – A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64149</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64149</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64148 – A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64148</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64148</strong></p>
  <p>A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64147 – Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64147</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64147</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64147</strong></p>
  <p>Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64147">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64146 – Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job confi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64146</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64146</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64146</strong></p>
  <p>Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64146">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64145 – Jenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64145</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64145</strong></p>
  <p>Jenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64144 – Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64144</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64144</strong></p>
  <p>Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64143 – Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64143</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64143</strong></p>
  <p>Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64142 – A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64142</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64142</strong></p>
  <p>A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64141 – A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Task Runner P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64141</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64141</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64140 – Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64140</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64140</strong></p>
  <p>Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary shell commands.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64139 – A missing permission check in Jenkins Start Windocks Containers Plugin 1.4 and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64139</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64139</strong></p>
  <p>A missing permission check in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64138 – A cross-site request forgery (CSRF) vulnerability in Jenkins Start Windocks Cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64138</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64138</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64137 – A missing permission check in Jenkins Themis Plugin 1.4.1 and earlier allows att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64137</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64137</strong></p>
  <p>A missing permission check in Jenkins Themis Plugin 1.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64136 – A cross-site request forgery (CSRF) vulnerability in Jenkins Themis Plugin 1.4.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64136</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64136</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Themis Plugin 1.4.1 and earlier allows attackers to connect to an attacker-specified HTTP server.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64135 – Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Jav...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64135</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64135</strong></p>
  <p>Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value, disabling a protection mechanism of the Java runtime.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64135">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64134 – Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64134</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64134</strong></p>
  <p>Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64133 – A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64133</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64133</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and earlier allows attackers to execute sandboxed Groovy code.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64132 – Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64132</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64132</strong></p>
  <p>Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64131 – Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64131</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64131</strong></p>
  <p>Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34212 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34212</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34212</guid>
    <pubDate>Mon, 29 Sep 2025 21:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34212</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.843 and Application prior to version 20.0.1923 (VA/SaaS deployments) possess CI/CD weaknesses: the build pulls an unverified third-party image, downloads the VirtualBox Extension Pack over plain HTTP without signature validation, and grants the jenkins account NOPASSWD for mount/umount. Together these allow supply c…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34212">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59476 – Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transfor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59476</guid>
    <pubDate>Wed, 17 Sep 2025 14:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59476</strong></p>
  <p>Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified content in log messages, allowing attackers able to control log message contents to insert line break characters, followed by forged log messages that may mislead administrators reviewing log output.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59475 – Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59475</guid>
    <pubDate>Wed, 17 Sep 2025 14:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59475</strong></p>
  <p>Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allowing attackers without Overall/Read permission to obtain limited information about the Jenkins configuration by listing available options in this menu (e.g., whether Credentials Plugin is installed).</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59474 – Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59474</guid>
    <pubDate>Wed, 17 Sep 2025 14:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59474</strong></p>
  <p>Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible to users lacking Overall/Read permission, allowing attackers without Overall/Read permission to list agent names through its sidepanel executors widget.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58460 – A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b_92b_cd6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58460</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58460</guid>
    <pubDate>Wed, 03 Sep 2025 15:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58460</strong></p>
  <p>A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b_92b_cd64 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58460">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58459 – Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perfor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58459</guid>
    <pubDate>Wed, 03 Sep 2025 15:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58459</strong></p>
  <p>Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58458 – In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58458</guid>
    <pubDate>Wed, 03 Sep 2025 15:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58458</strong></p>
  <p>In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53743 – Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API k...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53743</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53743</strong></p>
  <p>Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53742 – Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys une...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53742</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53742</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53742</strong></p>
  <p>Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53742">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53678 – Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53678</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53678</strong></p>
  <p>Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53677 – Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53677</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53677</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53677</strong></p>
  <p>Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attackers to observe and capture it.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53677">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53676 – Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53676</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53676</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53676</strong></p>
  <p>Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53676">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53675 – Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53675</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53675</strong></p>
  <p>Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53674 – Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53674</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53674</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53674</strong></p>
  <p>Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing the potential for attackers to observe and capture it.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53674">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53673 – Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53673</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53673</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53673</strong></p>
  <p>Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53673">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53672 – Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencryp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53672</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53672</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53672</strong></p>
  <p>Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53672">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53671 – Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Ke...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53671</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53671</strong></p>
  <p>Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53670 – Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53670</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53670</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53670</strong></p>
  <p>Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53670">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53669 – Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys display...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53669</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53669</strong></p>
  <p>Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53668 – Jenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53668</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53668</strong></p>
  <p>Jenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53667 – Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens disp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53667</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53667</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53667</strong></p>
  <p>Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53667">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53666 – Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53666</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53666</strong></p>
  <p>Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53665 – Jenkins Apica Loadtest Plugin 1.10 and earlier does not mask Apica Loadtest LTP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53665</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53665</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53665</strong></p>
  <p>Jenkins Apica Loadtest Plugin 1.10 and earlier does not mask Apica Loadtest LTP authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53665">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53664 – Jenkins Apica Loadtest Plugin 1.10 and earlier stores Apica Loadtest LTP authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53664</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53664</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53664</strong></p>
  <p>Jenkins Apica Loadtest Plugin 1.10 and earlier stores Apica Loadtest LTP authentication tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53664">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53663 – Jenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authenticati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53663</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53663</strong></p>
  <p>Jenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53662 – Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel K...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53662</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53662</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53662</strong></p>
  <p>Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53662">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53661 – Jenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53661</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53661</strong></p>
  <p>Jenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53660 – Jenkins QMetry Test Management Plugin 1.13 and earlier does not mask Qmetry Auto...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53660</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53660</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53660</strong></p>
  <p>Jenkins QMetry Test Management Plugin 1.13 and earlier does not mask Qmetry Automation API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53660">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53659 – Jenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53659</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53659</strong></p>
  <p>Jenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation API Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53658 – Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53658</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53658</strong></p>
  <p>Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53657 – Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM Li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53657</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53657</strong></p>
  <p>Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and passwords displayed on the job configuration form, increasing the potential for attackers to observe and capture them.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53656 – Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53656</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53656</strong></p>
  <p>Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53655 – Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53655</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53655</strong></p>
  <p>Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for attackers to observe and capture it.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53654 – Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53654</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53654</strong></p>
  <p>Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53653 – Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53653</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53653</strong></p>
  <p>Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53652 – Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53652</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53652</guid>
    <pubDate>Wed, 09 Jul 2025 16:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53652</strong></p>
  <p>Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with Item/Build permission to inject arbitrary values into Git parameters.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53652">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
