Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Jenkins Project — Vulnerabilities & Security Advisories 1473

Browse all 1473 CVE security advisories affecting Jenkins Project. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Jenkins is an open-source automation server primarily used for continuous integration and continuous delivery (CI/CD) pipelines. As a widely adopted tool in software development, it facilitates the building, testing, and deployment of code. Historically, the platform has been susceptible to numerous security flaws, with over 1,400 Common Vulnerabilities and Exposures (CVEs) recorded. These vulnerabilities frequently involve remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, often stemming from insecure default configurations or improper input validation. A notable incident occurred in 2019 when a critical RCE flaw allowed attackers to execute arbitrary commands on build agents. The Jenkins project has since implemented stricter security defaults and improved access controls to mitigate these risks. Despite these efforts, the sheer volume of historical CVEs highlights the complexity of securing a long-standing, feature-rich automation ecosystem, requiring diligent maintenance and configuration management by administrators to ensure robust protection against potential exploits.

CVE IDTitleCVSSSeverityPublished
CVE-2019-10324 CloudBees Jenkins Artifactory Plugin 跨站请求伪造漏洞 — Jenkins Artifactory Plugin 6.5 -2019-05-31
CVE-2019-10325 CloudBees Jenkins Warnings NG Plugin 跨站脚本漏洞 — Jenkins Warnings NG Plugin 5.4 -2019-05-31
CVE-2019-10326 CloudBees Jenkins Warnings NG Plugin 跨站请求伪造漏洞 — Jenkins Warnings NG Plugin 4.3 -2019-05-31
CVE-2019-10327 CloudBees Jenkins Pipeline Maven Integration Plugin 代码问题漏洞 — Jenkins Pipeline Maven Integration Plugin 8.1 -2019-05-31
CVE-2019-10328 CloudBees Pipeline Remote Loader Plugin 安全漏洞 — Jenkins Pipeline Remote Loader Plugin 9.9 -2019-05-31
CVE-2019-10329 CloudBees Jenkins InfluxDB Plugin 信任管理问题漏洞 — Jenkins InfluxDB Plugin 8.8 -2019-05-31
CVE-2019-10330 CloudBees Jenkins Gitea Plugin 访问控制错误漏洞 — Jenkins Gitea Plugin 7.5 -2019-05-31
CVE-2019-10319 CloudBees Jenkins PAM Authentication Plugin 授权问题漏洞 — Jenkins PAM Authentication Plugin 4.3 -2019-05-21
CVE-2019-10320 CloudBees Jenkins Credentials Plugin 信息泄露漏洞 — Jenkins Credentials Plugin 4.3 -2019-05-21
CVE-2019-10316 CloudBees Jenkins Aqua MicroScanner Plugin 信任管理问题漏洞 — Jenkins Aqua MicroScanner Plugin 8.8 -2019-04-30
CVE-2019-10317 CloudBees Jenkins SiteMonitor Plugin 信任管理问题漏洞 — Jenkins SiteMonitor Plugin 6.5 -2019-04-30
CVE-2019-10318 CloudBees Jenkins Azure AD Plugin 信任管理问题漏洞 — Jenkins Azure AD Plugin 8.1 -2019-04-30
CVE-2019-10307 CloudBees Jenkins Static Analysis Utilities Plugin 跨站请求伪造漏洞 — Jenkins Static Analysis Utilities Plugin 6.5 -2019-04-30
CVE-2019-10308 CloudBees Jenkins Static Analysis Utilities Plugin 授权问题漏洞 — Jenkins Static Analysis Utilities Plugin 6.5 -2019-04-30
CVE-2019-10309 CloudBees Jenkins Self-Organizing Swarm Plug-in Modules Plugin 代码问题漏洞 — Jenkins Self-Organizing Swarm Plug-in Modules Plugin 7.4 -2019-04-30
CVE-2019-10310 CloudBees Jenkins Ansible Tower Plugin 跨站请求伪造漏洞 — Jenkins Ansible Tower Plugin 8.8 -2019-04-30
CVE-2019-10311 CloudBees Jenkins Ansible Tower Plugin 信任管理问题漏洞 — Jenkins Ansible Tower Plugin 8.1 -2019-04-30
CVE-2019-10312 CloudBees Jenkins Ansible Tower Plugin 信任管理问题漏洞 — Jenkins Ansible Tower Plugin 4.3 -2019-04-30
CVE-2019-10313 CloudBees Jenkins Twitter Plugin 信任管理问题漏洞 — Jenkins Twitter Plugin 8.8 -2019-04-30
CVE-2019-10314 CloudBees Jenkins Koji Plugin 信任管理问题漏洞 — Jenkins Koji Plugin 6.5 -2019-04-30
CVE-2019-10315 CloudBees Jenkins GitHub Authentication Plugin 跨站请求伪造漏洞 — Jenkins GitHub Authentication Plugin 8.8 -2019-04-30
CVE-2019-10300 CloudBees Jenkins GitLab Plugin 跨站请求伪造漏洞 — Jenkins GitLab Plugin 8.8 -2019-04-18
CVE-2019-10301 CloudBees Jenkins GitLab Plugin 信任管理问题漏洞 — Jenkins GitLab Plugin 6.5 -2019-04-18
CVE-2019-10302 CloudBees Jenkins jira-ext Plugin 信任管理问题漏洞 — Jenkins jira-ext Plugin 8.8 -2019-04-18
CVE-2019-10303 CloudBees Jenkins Azure PublisherSettings Credentials Plugin 信任管理问题漏洞 — Jenkins Azure PublisherSettings Credentials Plugin 8.8 -2019-04-18
CVE-2019-10304 CloudBees Jenkins XebiaLabs XL Deploy Plugin 跨站请求伪造漏洞 — Jenkins XebiaLabs XL Deploy Plugin 6.5 -2019-04-18
CVE-2019-10305 CloudBees Jenkins XebiaLabs XL Deploy Plugin 权限许可和访问控制问题漏洞 — Jenkins XebiaLabs XL Deploy Plugin 6.5 -2019-04-18
CVE-2019-10306 CloudBees Jenkins ontrack Plugin 安全特征问题漏洞 — Jenkins ontrack Plugin 9.9 -2019-04-18
CVE-2019-1003050 CloudBees Jenkins 跨站脚本漏洞 — Jenkins 5.4 -2019-04-10
CVE-2019-1003049 CloudBees Jenkins 代码问题漏洞 — Jenkins 9.8 -2019-04-10

This page lists every published CVE security advisory associated with Jenkins Project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.