Browse Security Advisories
Security Advisories for org.jenkins-ci.main:jenkins-core Clear Filters
Moderate
5 months ago
Jenkins cross-site request forgery (CSRF) vulnerability
maven
org.jenkins-ci.main:jenkins-core
Moderate
5 months ago
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
maven
org.jenkins-ci.main:jenkins-core
Moderate
5 months ago
Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
maven
org.jenkins-ci.main:jenkins-core
Moderate
10 months ago
Jenkins exposes multi-line secrets through error messages
maven
org.jenkins-ci.main:jenkins-core
Moderate
10 months ago
Jenkins item creation restriction bypass vulnerability
maven
org.jenkins-ci.main:jenkins-core
Moderate
12 months ago
Jenkins does not perform a permission check in an HTTP endpoint
maven
org.jenkins-ci.main:jenkins-core
High
12 months ago
Jenkins Remoting library arbitrary file read vulnerability
maven
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:remoting
High
over 1 year ago
Cross-site WebSocket hijacking vulnerability in the Jenkins CLI
maven
org.jenkins-ci.main:jenkins-core
Critical
over 1 year ago
Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE
maven
org.jenkins-ci.main:jenkins-core
Moderate
almost 2 years ago
Jenkins does not exclude sensitive build variables from search
maven
org.jenkins-ci.main:jenkins-core
Low
almost 2 years ago
Jenkins temporary uploaded file created with insecure permissions
maven
org.jenkins-ci.main:jenkins-core
High
almost 2 years ago
Jenkins temporary plugin file created with insecure permissions
maven
org.jenkins-ci.main:jenkins-core
Low
almost 2 years ago
Jenkins temporary uploaded file created with insecure permissions
maven
org.jenkins-ci.main:jenkins-core
High
almost 2 years ago
Jenkins Cross-site Scripting vulnerability
maven
org.jenkins-ci.main:jenkins-core
High
about 2 years ago
Jenkins Stored Cross-site Scripting vulnerability
maven
org.jenkins-ci.main:jenkins-core
High
about 2 years ago
Jenkins CSRF protection bypass vulnerability
maven
org.jenkins-ci.main:jenkins-core
Moderate
over 2 years ago
Incorrect Permission Preservation in Jenkins Core
maven
org.jenkins-ci.main:jenkins-core
Low
over 2 years ago
Information disclosure through error stack traces related to agents
maven
org.jenkins-ci.main:jenkins-core
High
over 2 years ago
Incorrect Authorization in Jenkins Core
maven
org.jenkins-ci.main:jenkins-core
High
over 2 years ago
Cross-site Scripting vulnerability in Jenkins
maven
org.jenkins-ci.main:jenkins-core
High
almost 3 years ago
Jenkins vulnerable to stored cross site scripting in the I:helpIcon component
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Cross-site Scripting vulnerability in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Observable timing discrepancy allows determining username validity in Jenkins
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Cross-site Scripting vulnerability in Jenkins
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Cross-site Scripting vulnerability in Jenkins
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Cross-site Scripting vulnerability in Jenkins
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Unauthorized view fragment access in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Improper Neutralization of Input During Web Page Generation in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Improper Neutralization of Input During Web Page Generation in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Improper Neutralization of Input During Web Page Generation in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Improper Neutralization of Input During Web Page Generation in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Improper Neutralization of Input During Web Page Generation in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Critical
about 3 years ago
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Critical
about 3 years ago
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Critical
about 3 years ago
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Critical
about 3 years ago
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Critical
about 3 years ago
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Critical
about 3 years ago
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Critical
about 3 years ago
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Critical
about 3 years ago
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Critical
about 3 years ago
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Critical
about 3 years ago
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Critical
about 3 years ago
Agent-to-controller access control allows reading/writing most content of build directories in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Critical
about 3 years ago
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Agent-to-controller access control allowed writing to sensitive directory used by Jenkins Pipeline: Shared Groovy Libraries Plugin
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Improper handling of equivalent directory names on Windows in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Path traversal vulnerability on Windows in Jenkins
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Session fixation vulnerability in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Improper permission checks allow canceling queue items and aborting builds in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
View name validation bypass in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Lack of type validation in agent related REST API in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Time-of-check Time-of-use (TOCTOU) Race Condition in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Reflected XSS vulnerability in Jenkins markup formatter preview
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Excessive memory allocation in graph URLs leads to denial of service in Jenkins
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Path traversal vulnerability in Jenkins agent names
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Stored XSS vulnerability in Jenkins on new item page
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Missing permission check for paths with specific prefix in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
XSS vulnerability in Jenkins notification bar
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Improper handling of REST API XML deserialization errors in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Arbitrary file read vulnerability in workspace browsers in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Arbitrary file existence check in file fingerprints in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Stored XSS vulnerability in Jenkins button labels
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Jenkins Cross-site Scripting vulnerability in project naming strategy
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Improper Neutralization of Input During Web Page Generation in Jenkins
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Jenkins Cross-Site Scripting vulnerability in help icons
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Stored XSS vulnerability in Jenkins 'keep forever' badge icon
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Stored XSS vulnerability in Jenkins job build time trend
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Stored XSS vulnerability in Jenkins upstream cause
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Stored XSS vulnerability in Jenkins console links
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Improper Neutralization of Input During Web Page Generation in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Improper Neutralization of Input During Web Page Generation in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Improper Neutralization of Input During Web Page Generation in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Low
about 3 years ago
Jenkins REST APIs vulnerable to clickjacking
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Memory usage graphs accessible to anyone with Overall/Read
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Non-constant time comparison of inbound TCP agent connection secret
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Jenkins vulnerable to UDP amplification reflection attack
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Jenkins Diagnostic page exposed session cookies
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
Inbound TCP Agent Protocol/3 authentication bypass in Jenkins
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
XML external entity (XXE) vulnerability in Jenkins
maven
org.jenkins-ci.main:jenkins-core
High
about 3 years ago
XML external entity (XXE) vulnerability in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Improper Neutralization of Input During Web Page Generation in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Missing Authorization in Jenkins
maven
org.kohsuke.stapler:stapler-parent, org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Improper Limitation of a Pathname to a Restricted Directory in Jenkins
maven
org.jenkins-ci.main:jenkins-core
Low
about 3 years ago
Jenkins allows Cross-Site Scripting (XSS)
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Jenkins allows Remote Attackers to Hijack Sessions
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Jenkins allows attackers to configure restricted projects
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Jenkins allows attackers to execute arbitrary jobs
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Jenkins does not invalidate the API token when a user is deleted
maven
org.jenkins-ci.main:jenkins-core
Moderate
about 3 years ago
Jenkin allows attackers to obtain passwords by reading the HTML source code
maven
org.jenkins-ci.main:jenkins-core
Filter by Severity
Filter by Ecosystem
maven
6,662
packagist
5,355
pypi
4,831
npm
4,188
go
2,795
nuget
1,700
cargo
1,065
rubygems
918
hex
37
swift
35
actions
32
pub
10
Filter by Package
tensorflow
433
tensorflow-gpu
427
tensorflow-cpu
423
moodle/moodle
418
magento/community-edition
300
Microsoft.ChakraCore
247
org.jenkins-ci.main:jenkins-core
239
typo3/cms
190
org.apache.tomcat:tomcat
138
pimcore/pimcore
120
dolibarr/dolibarr
116
github.com/mattermost/mattermost/server/v8
115
typo3/cms-core
111
com.liferay.portal:release.portal.bom
110
phpmyadmin/phpmyadmin
107
Django
107
com.liferay.portal:release.dxp.bom
105
drupal/core
103
magento/project-community-edition
100
microweber/microweber
99
silverstripe/framework
92
apache-airflow
85
drupal/drupal
83
librenms/librenms
82
thorsten/phpmyfaq
73
Plone
72
symfony/symfony
69
com.fasterxml.jackson.core:jackson-databind
69
concrete5/concrete5
65
github.com/usememos/memos
65
salt
65
ansible
63
actionpack
61
shopware/platform
57
apache-superset
57
org.apache.struts:struts2-core
57
github.com/grafana/grafana
56
mlflow
53
craftcms/cms
51
org.keycloak:keycloak-core
50
nova
48
baserproject/basercms
47
django
46
nokogiri
46
org.apache.tomcat.embed:tomcat-embed-core
46
shopware/core
45
mautic/core
44
github.com/rancher/rancher
44
vyper
44
gradio
44
matrix-synapse
42
nilsteampassnet/teampass
42
rdiffweb
42
plone
41
org.keycloak:keycloak-services
41
k8s.io/kubernetes
41
org.xwiki.platform:xwiki-platform-oldcore
41
org.elasticsearch:elasticsearch
41
mantisbt/mantisbt
41
showdoc/showdoc
41
github.com/hashicorp/vault
40
froxlor/froxlor
40
intelliants/subrion
39
github.com/mattermost/mattermost-server/v6
39
directus
38
com.thoughtworks.xstream:xstream
37
snipe/snipe-it
36
com.jfinal:jfinal
36
net.mingsoft:ms-mcms
36
moin
35
org.jenkins-ci.plugins:script-security
34
zendframework/zendframework1
34
github.com/answerdev/answer
34
io.undertow:undertow-core
34
parse-server
33
gogs.io/gogs
33
keystone
32
github.com/cilium/cilium
31
opencv-contrib-python
31
Pillow
31
github.com/argoproj/argo-cd
31
github.com/argoproj/argo-cd/v2
31
github.com/hashicorp/nomad
31
opencv-python
31
shopware/shopware
30
getgrav/grav
30
github.com/mattermost/mattermost-server
29
rack
29
github.com/docker/docker
29
github.com/hashicorp/consul
29
mediawiki/core
28
org.apache.solr:solr-core
28
electron
28
org.opencms:opencms-core
27
centreon/centreon
27
prestashop/prestashop
26
pillow
26
openssl-src
26
org.springframework.security:spring-security-core
26
next
26
rubygems-update
25
org.eclipse.jetty:jetty-server
25
contao/core-bundle
25
open-webui
25
pocketmine/pocketmine-mp
24
github.com/traefik/traefik/v2
24
org.keycloak:keycloak-parent
24
getkirby/cms
24
magento/core
24
surrealdb
24
grumpydictator/firefly-iii
23
simplesamlphp/simplesamlphp
23
phpoffice/phpexcel
23
laravel/framework
23
remdex/livehelperchat
23
puppet
23
zendframework/zendframework
23
vllm
23
Microsoft.AspNetCore.App.Runtime.win-x64
22
tribalsystems/zenario
22
org.bouncycastle:bcprov-jdk14
22
@openzeppelin/contracts-upgradeable
22
org.apache.openmeetings:openmeetings-parent
22
ckb
22
DotNetNuke.Core
22
Microsoft.AspNetCore.App.Runtime.win-x86
22
phpoffice/phpspreadsheet
21
activerecord
21
@openzeppelin/contracts
21
github.com/goharbor/harbor
21
github.com/ethereum/go-ethereum
21
org.apache.nifi:nifi
21
glance
21
Microsoft.AspNetCore.App.Runtime.win-arm
21
org.apache.tomcat:tomcat-catalina
21
org.cloudfoundry.identity:cloudfoundry-identity-server
20
aim
20
wasmtime
20
code.gitea.io/gitea
20
funadmin/funadmin
20
cockpit-hq/cockpit
20
golang.org/x/net
20
langchain
20
Microsoft.AspNetCore.App.Runtime.linux-musl-x64
19
org.apache.tomcat:tomcat-coyote
19
github.com/zitadel/zitadel
19
org.xwiki.platform:xwiki-platform-web-templates
19
helm.sh/helm/v3
19
Microsoft.AspNetCore.App.Runtime.linux-arm64
19
Microsoft.AspNetCore.App.Runtime.linux-x64
19
Microsoft.AspNetCore.App.Runtime.osx-x64
19
Microsoft.AspNetCore.App.Runtime.win-arm64
19
pyload-ng
19
Microsoft.AspNetCore.App.Runtime.linux-arm
19
deno
19
neutron
19
topthink/framework
18
com.vaadin:vaadin-bom
18
genix/cms
18
cobbler
18
forkcms/forkcms
18
contao/contao
18
mercurial
18
mindsdb
18
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
18
opencart/opencart
17
cryptography
17
typo3/cms-backend
17
org.springframework:spring-core
17
cakephp/cakephp
17
openmage/magento-lts
17
calibreweb
17
yetiforce/yetiforce-crm
17
org.apache.geode:geode-core
17
ezsystems/ezpublish-kernel
17
notebook
17
OctoPrint
17
symfony/security
17
francoisjacquet/rosariosis
17
org.apache.inlong:manager-pojo
17
paddlepaddle
16
org.apache.jspwiki:jspwiki-main
16
org.bouncycastle:bcprov-jdk15
16
org.apache.ranger:ranger
16
org.apache.activemq:activemq-client
16
rusqlite
16
Microsoft.NetCore.App.Runtime.win-x86
16
Microsoft.NetCore.App.Runtime.win-x64
16
tinymce
16
Microsoft.NetCore.App.Runtime.win-arm64
16
Microsoft.NetCore.App.Runtime.win-arm
16
lollms
16
sequelize
16
phpbb/phpbb
16
org.apache.dubbo:dubbo
16
github.com/traefik/traefik/v3
16
october/system
16
ethyca-fides
16
PaddlePaddle
16
github.com/openfga/openfga
16