← Back to feed Search feed

Jenkins vulnerabilities

21 entries matching jenkins — updated 2026-09-19 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-92122Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy creaHIGH8.848%ileNVD2026-09-16
CVE-2026-92123Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiHIGH8.847%ileNVD2026-09-16
CVE-2026-92124Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elemHIGH8.847%ileNVD2026-09-16
CVE-2026-92125Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotHIGH8.843%ileNVD2026-09-16
CVE-2026-92137Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot FrameworHIGH8.854%ileNVD2026-09-16
CVE-2026-92127Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an itemHIGH8.040%ileNVD2026-09-16
CVE-2026-92134Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job confiHIGH8.032%ileNVD2026-09-16
CVE-2026-92135Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuratHIGH8.032%ileNVD2026-09-16
CVE-2026-92136Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the HIGH8.032%ileNVD2026-09-16
CVE-2026-92128Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirmingHIGH7.513%ileNVD2026-09-16
CVE-2026-92129Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods HIGH7.538%ileNVD2026-09-16
CVE-2026-92140Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in MEDIUM6.834%ileNVD2026-09-16
CVE-2026-92139Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, includinMEDIUM6.522%ileNVD2026-09-16
CVE-2026-92132Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected iMEDIUM5.416%ileNVD2026-09-16
CVE-2026-92133Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API toMEDIUM5.413%ileNVD2026-09-16
CVE-2026-92141Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackMEDIUM4.326%ileNVD2026-09-16
CVE-2026-92131Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to MEDIUM4.213%ileNVD2026-09-16
CVE-2026-92138The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callbMEDIUM4.21%ileNVD2026-09-16
CVE-2026-92130Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentialsLOW3.112%ileNVD2026-09-16
CVE-2026-92126Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStratUNKNOWN10%ileNVD2026-09-16
OSS-20260916-5Multiple vulnerabilities in Jenkins pluginsUNKNOWNOSS-Security2026-09-16