Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Jenkins project — Vulnerabilities & Security Advisories 1473

Browse all 1473 CVE security advisories affecting Jenkins project. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Jenkins is an open-source automation server primarily used for continuous integration and continuous delivery (CI/CD) pipelines. As a widely adopted tool in software development, it facilitates the building, testing, and deployment of code. Historically, the platform has been susceptible to numerous security flaws, with over 1,400 Common Vulnerabilities and Exposures (CVEs) recorded. These vulnerabilities frequently involve remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, often stemming from insecure default configurations or improper input validation. A notable incident occurred in 2019 when a critical RCE flaw allowed attackers to execute arbitrary commands on build agents. The Jenkins project has since implemented stricter security defaults and improved access controls to mitigate these risks. Despite these efforts, the sheer volume of historical CVEs highlights the complexity of securing a long-standing, feature-rich automation ecosystem, requiring diligent maintenance and configuration management by administrators to ensure robust protection against potential exploits.

CVE IDTitleCVSSSeverityPublished
CVE-2019-10362 CloudBees Jenkins Configuration as Code Plugin 输入验证错误漏洞 — Jenkins Configuration as Code Plugin 5.4 -2019-07-31
CVE-2019-10363 CloudBees Jenkins Configuration as Code Plugin 信息泄露漏洞 — Jenkins Configuration as Code Plugin 6.5 -2019-07-31
CVE-2019-10364 CloudBees Jenkins Amazon EC2 Plugin 信息泄露漏洞 — Jenkins Amazon EC2 Plugin 5.5 -2019-07-31
CVE-2019-10365 CloudBees Jenkins Google Kubernetes Engine Plugin 信息泄露漏洞 — Jenkins Google Kubernetes Engine Plugin 4.3 -2019-07-31
CVE-2019-10366 CloudBees Jenkins Skytap Cloud CI Plugin 信任管理问题漏洞 — Jenkins Skytap Cloud CI Plugin 8.8 -2019-07-31
CVE-2019-10343 CloudBees Jenkins Configuration as Code插件日志信息泄露漏洞 — Jenkins Configuration as Code Plugin 3.3 -2019-07-31
CVE-2019-10352 CloudBees Jenkins 路径遍历漏洞 — Jenkins 6.5 -2019-07-17
CVE-2019-10353 CloudBees Jenkins 跨站请求伪造漏洞 — Jenkins 7.5 -2019-07-17
CVE-2019-10354 CloudBees Jenkins 信息泄露漏洞 — Jenkins 4.3 -2019-07-17
CVE-2019-10340 CloudBees Jenkins Docker插件跨站请求伪造漏洞 — Jenkins Docker Plugin 8.8 -2019-07-11
CVE-2019-10341 CloudBees Jenkins Docker插件信息泄露漏洞 — Jenkins Docker Plugin 8.1 -2019-07-11
CVE-2019-10342 CloudBees Jenkins Docker插件信息泄露漏洞 — Jenkins Docker Plugin 4.3 -2019-07-11
CVE-2019-10346 CloudBees Jenkins Embeddable Build Status插件跨站脚本漏洞 — Jenkins Embeddable Build Status Plugin 6.1 -2019-07-11
CVE-2019-10347 CloudBees Jenkins Mashup Portlets插件信任管理问题漏洞 — Jenkins Mashup Portlets Plugin 8.8 -2019-07-11
CVE-2019-10348 CloudBees Jenkins Gogs插件信息泄露漏洞 — Jenkins Gogs Plugin 8.8 -2019-07-11
CVE-2019-10349 CloudBees Jenkins Dependency Graph Viewer插件跨站脚本漏洞 — Jenkins Dependency Graph Viewer Plugin 5.4 -2019-07-11
CVE-2019-10350 CloudBees Jenkins Port Allocator插件信息泄露漏洞 — Jenkins Port Allocator Plugin 8.8 -2019-07-11
CVE-2019-10351 CloudBees Jenkins Caliper CI Plugin 信息泄露漏洞 — Jenkins Caliper CI Plugin 8.8 -2019-07-11
CVE-2019-10337 CloudBees Jenkins Token Macro Plugin 代码问题漏洞 — Jenkins Token Macro Plugin 8.1 -2019-06-11
CVE-2019-10338 CloudBees Jenkins JX Resources Plugin 跨站请求伪造漏洞 — Jenkins JX Resources Plugin 8.8 -2019-06-11
CVE-2019-10339 CloudBees Jenkins JX Resources Plugin 信任管理问题漏洞 — Jenkins JX Resources Plugin 8.1 -2019-06-11
CVE-2019-10331 CloudBees Jenkins ElectricFlow Plugin 跨站请求伪造漏洞 — Jenkins ElectricFlow Plugin 4.3 -2019-06-11
CVE-2019-10332 CloudBees Jenkins ElectricFlow Plugin 授权问题漏洞 — Jenkins ElectricFlow Plugin 4.3 -2019-06-11
CVE-2019-10333 CloudBees Jenkins ElectricFlow Plugin 信息泄露漏洞 — Jenkins ElectricFlow Plugin 4.3 -2019-06-11
CVE-2019-10334 CloudBees Jenkins ElectricFlow Plugin 信任管理问题漏洞 — Jenkins ElectricFlow Plugin 8.2 -2019-06-11
CVE-2019-10335 CloudBees Jenkins ElectricFlow Plugin 跨站脚本漏洞 — Jenkins ElectricFlow Plugin 5.4 -2019-06-11
CVE-2019-10336 CloudBees Jenkins ElectricFlow Plugin 跨站脚本漏洞 — Jenkins ElectricFlow Plugin 6.1 -2019-06-11
CVE-2019-10321 CloudBees Jenkins Artifactory Plugin 跨站请求伪造漏洞 — Jenkins Artifactory Plugin 8.8 -2019-05-31
CVE-2019-10322 CloudBees Jenkins Artifactory Plugin 授权问题漏洞 — Jenkins Artifactory Plugin 6.5 -2019-05-31
CVE-2019-10323 CloudBees Jenkins Artifactory Plugin 授权问题漏洞 — Jenkins Artifactory Plugin 4.3 -2019-05-31

This page lists every published CVE security advisory associated with Jenkins project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.