Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Jenkins project — Vulnerabilities & Security Advisories 1473

Browse all 1473 CVE security advisories affecting Jenkins project. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Jenkins is an open-source automation server primarily used for continuous integration and continuous delivery (CI/CD) pipelines. As a widely adopted tool in software development, it facilitates the building, testing, and deployment of code. Historically, the platform has been susceptible to numerous security flaws, with over 1,400 Common Vulnerabilities and Exposures (CVEs) recorded. These vulnerabilities frequently involve remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, often stemming from insecure default configurations or improper input validation. A notable incident occurred in 2019 when a critical RCE flaw allowed attackers to execute arbitrary commands on build agents. The Jenkins project has since implemented stricter security defaults and improved access controls to mitigate these risks. Despite these efforts, the sheer volume of historical CVEs highlights the complexity of securing a long-standing, feature-rich automation ecosystem, requiring diligent maintenance and configuration management by administrators to ensure robust protection against potential exploits.

CVE IDTitleCVSSSeverityPublished
CVE-2019-10287 CloudBees Jenkins youtrack-plugin Plugin 信任管理问题漏洞 — Jenkins youtrack-plugin Plugin 8.8 -2019-04-04
CVE-2019-10288 CloudBees Jenkins Jabber Server Plugin 信任管理问题漏洞 — Jenkins Jabber Server Plugin 8.8 -2019-04-04
CVE-2019-10289 CloudBees Jenkins Netsparker Cloud Scan Plugin 跨站请求伪造漏洞 — Jenkins Netsparker Cloud Scan Plugin 6.5 -2019-04-04
CVE-2019-10290 CloudBees Jenkins Netsparker Cloud Scan Plugin 授权问题漏洞 — Jenkins Netsparker Cloud Scan Plugin 6.5 -2019-04-04
CVE-2019-10291 CloudBees Jenkins Netsparker Cloud Scan Plugin 信任管理问题漏洞 — Jenkins Netsparker Cloud Scan Plugin 8.8 -2019-04-04
CVE-2019-10292 CloudBees Jenkins Kmap Plugin 跨站请求伪造漏洞 — Jenkins Kmap Plugin 6.5 -2019-04-04
CVE-2019-10293 CloudBees Jenkins Kmap Plugin 授权问题漏洞 — Jenkins Kmap Plugin 6.5 -2019-04-04
CVE-2019-10294 CloudBees Jenkins Kmap Plugin 信任管理问题漏洞 — Jenkins Kmap Plugin 8.8 -2019-04-04
CVE-2019-10295 CloudBees Jenkins crittercism-dsym Plugin 信任管理问题漏洞 — Jenkins crittercism-dsym Plugin 8.3 -2019-04-04
CVE-2019-10296 CloudBees Jenkins Serena SRA Deploy Plugin 信任管理问题漏洞 — Jenkins Serena SRA Deploy Plugin 8.8 -2019-04-04
CVE-2019-10297 CloudBees Jenkins Sametime Plugin 信任管理问题漏洞 — Jenkins Sametime Plugin 7.8 -2019-04-04
CVE-2019-10298 CloudBees Jenkins Koji Plugin 信任管理问题漏洞 — Jenkins Koji Plugin 7.8 -2019-04-04
CVE-2019-10299 CloudBees Jenkins CloudCoreo DeployTime Plugin 信任管理问题漏洞 — Jenkins CloudCoreo DeployTime Plugin 8.8 -2019-04-04
CVE-2019-1003083 CloudBees Jenkins Gearman Plugin 授权问题漏洞 — Jenkins Gearman Plugin 6.5 -2019-04-04
CVE-2019-1003084 CloudBees Jenkins Zephyr Enterprise Test Management Plugin 跨站请求伪造漏洞 — Jenkins Zephyr Enterprise Test Management Plugin 6.5 -2019-04-04
CVE-2019-1003085 CloudBees Jenkins Zephyr Enterprise Test Management Plugin 授权问题漏洞 — Jenkins Zephyr Enterprise Test Management Plugin 6.5 -2019-04-04
CVE-2019-1003086 CloudBees Jenkins Chef Sinatra Plugin 跨站请求伪造漏洞 — Jenkins Chef Sinatra Plugin 6.5 -2019-04-04
CVE-2019-1003087 CloudBees Jenkins Chef Sinatra Plugin 授权问题漏洞 — Jenkins Chef Sinatra Plugin 6.5 -2019-04-04
CVE-2019-1003088 CloudBees Jenkins Fabric Beta Publisher Plugin 信任管理问题漏洞 — Jenkins Fabric Beta Publisher Plugin 8.8 -2019-04-04
CVE-2019-1003089 CloudBees Jenkins Upload to pgyer Plugin 信任管理问题漏洞 — Jenkins Upload to pgyer Plugin 8.8 -2019-04-04
CVE-2019-1003090 CloudBees Jenkins SOASTA CloudTest Plugin 跨站请求伪造漏洞 — Jenkins SOASTA CloudTest Plugin 6.5 -2019-04-04
CVE-2019-1003091 CloudBees Jenkins SOASTA CloudTest Plugin 授权问题漏洞 — Jenkins SOASTA CloudTest Plugin 6.5 -2019-04-04
CVE-2019-1003092 CloudBees Jenkins Nomad Plugin 跨站请求伪造漏洞 — Jenkins Nomad Plugin 6.5 -2019-04-04
CVE-2019-1003093 CloudBees Jenkins Nomad Plugin 授权问题漏洞 — Jenkins Nomad Plugin 6.5 -2019-04-04
CVE-2019-1003094 CloudBees Jenkins Open STF Plugin 信任管理问题漏洞 — Jenkins Open STF Plugin 7.8 -2019-04-04
CVE-2019-1003095 CloudBees Jenkins Perfecto Mobile Plugin 信任管理问题漏洞 — Jenkins Perfecto Mobile Plugin 7.8 -2019-04-04
CVE-2019-1003096 CloudBees Jenkins TestFairy Plugin 信任管理问题漏洞 — Jenkins TestFairy Plugin 8.8 -2019-04-04
CVE-2019-1003097 CloudBees Jenkins Crowd Integration Plugin 信任管理问题漏洞 — Jenkins Crowd Integration Plugin 7.8 -2019-04-04
CVE-2019-1003098 CloudBees Jenkins openid Plugin 跨站请求伪造漏洞 — Jenkins openid Plugin 6.5 -2019-04-04
CVE-2019-1003099 CloudBees Jenkins openid Plugin 授权问题漏洞 — Jenkins openid Plugin 6.5 -2019-04-04

This page lists every published CVE security advisory associated with Jenkins project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.