Jenkins

Jenkins is a free and open source automation server. It helps automate the parts of software development related to building testing and deploying facilitating continuous integration and continuous delivery. It is a server-based system that runs in servlet containers such as Apache Tomcat.

Severity Summary:

Critical: 19 High: 54 Medium: 155 Low: 10
Reference
Title
Severity
Jenkins Improper Input Validation Vulnerability
High
Jenkins Uncontrolled Resource Consumption Vulnerability
High
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability
High
Jenkins Use of Insufficiently Random Values Vulnerability
High
Jenkins Deserialization of Untrusted Data Vulnerability
High
Jenkins Insufficient Session Expiration Vulnerability
High
Jenkins Missing Release of Resource after Effective Lifetime Vulnerability
High
Jenkins Insufficient Session Expiration Vulnerability
High
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability
High
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability
High
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
High
Jenkins Insufficient Session Expiration Vulnerability
High
Jenkins Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
High
Jenkins Observable Differences in Behavior to Error Inputs Vulnerability
Medium
Jenkins Other Vulnerability
Medium
Jenkins Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Jenkins Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Jenkins Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Jenkins Observable Differences in Behavior to Error Inputs Vulnerability
Medium
Jenkins Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability
Medium
Jenkins Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Medium
Jenkins Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Jenkins Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Jenkins Incorrect Authorization Vulnerability
Medium
Jenkins Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Jenkins Other Vulnerability
Medium
Jenkins 7PK - Security Features Vulnerability
Medium
Jenkins 7PK - Security Features Vulnerability
Medium