Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Jenkins — Vulnerabilities & Security Advisories 146

All 146 CVE vulnerabilities found in Jenkins, with AI-generated Chinese analysis, references, and POCs.

This page documents known software weaknesses associated with Jenkins, a popular open-source automation server. It aggregates security vulnerability data specifically linked to the Jenkins product ecosystem, providing a centralized view of issues that affect this widely used continuous integration and delivery platform. The content here collects a wide range of vulnerability types, including improper access control, cross-site scripting, injection flaws, and unsafe deserialization issues. The data covers historical records spanning several years, capturing the evolution of security postures and the remediation efforts undertaken by the Jenkins project over time. This comprehensive scope allows users to analyze trends and understand how specific weaknesses have been addressed in various releases. Readers can use this resource to track vendor advisories and understand the severity and context of a particular weakness class. It enables you to look up a product's vulnerability history to assess risk exposure and prioritize patching strategies. By examining these aggregated records, security teams can better understand the attack surface of their Jenkins instances and make informed decisions about configuration hardening and upgrade paths. The information serves as a factual reference for evaluating the current security state of Jenkins deployments against known public disclosures, supporting more robust vulnerability management practices without resorting to speculative or marketing-driven narratives.

Vendor: Jenkins project

CVE ID Title CVSS Severity Published
CVE-2019-10406 CloudBees Jenkins 跨站脚本漏洞 4.8 - 2019-09-25
CVE-2019-10384 CloudBees Jenkins 跨站请求伪造漏洞 8.8 - 2019-08-28
CVE-2019-10383 CloudBees Jenkins 跨站脚本漏洞 4.8 - 2019-08-28
CVE-2019-1010241 CloudBees Jenkins Credentials Binding Plugin Jenkins插件信任管理问题漏洞 CWE-257 6.5 - 2019-07-19
CVE-2019-10352 CloudBees Jenkins 路径遍历漏洞 6.5 - 2019-07-17
CVE-2019-10353 CloudBees Jenkins 跨站请求伪造漏洞 7.5 - 2019-07-17
CVE-2019-10354 CloudBees Jenkins 信息泄露漏洞 4.3 - 2019-07-17
CVE-2019-1003050 CloudBees Jenkins 跨站脚本漏洞 5.4 - 2019-04-10
CVE-2019-1003049 CloudBees Jenkins 代码问题漏洞 9.8 - 2019-04-10
CVE-2019-1003003 CloudBees Jenkins 代码问题漏洞 8.8 - 2019-01-22
CVE-2019-1003004 CloudBees Jenkins 代码问题漏洞 8.3 - 2019-01-22
CVE-2017-2598 CloudBees Jenkins 信息泄露漏洞 CWE-325 4.3 - 2018-05-23
CVE-2017-2609 CloudBees Jenkins 安全漏洞 CWE-200 5.3 - 2018-05-22
CVE-2017-2607 CloudBees Jenkins 跨站脚本漏洞 CWE-79 5.4 - 2018-05-21
CVE-2017-2613 CloudBees Jenkins 跨站请求伪造漏洞 CWE-770 4.3 - 2018-05-15
CVE-2017-2602 CloudBees Jenkins 安全漏洞 CWE-184 4.3 - 2018-05-15
CVE-2017-2603 CloudBees Jenkins 信息泄露漏洞 CWE-325 4.3 - 2018-05-15
CVE-2017-2604 CloudBees Jenkins 权限许可和访问控制漏洞 CWE-358 6.5 - 2018-05-15
CVE-2017-2610 CloudBees Jenkins 跨站脚本漏洞 CWE-79 5.4 - 2018-05-15
CVE-2017-2600 CloudBees Jenkins 信息泄露漏洞 CWE-325 4.3 - 2018-05-15
CVE-2017-2608 CloudBees Jenkins 安全漏洞 CWE-502 9.8 - 2018-05-15
CVE-2017-2612 CloudBees Jenkins 安全漏洞 CWE-358 5.4 - 2018-05-15
CVE-2017-2601 CloudBees Jenkins 跨站脚本漏洞 CWE-79 5.4 - 2018-05-10
CVE-2017-2606 CloudBees Jenkins 信息泄露漏洞 CWE-200 4.3 - 2018-05-08
CVE-2017-2611 CloudBees Jenkins 安全漏洞 CWE-358 4.3 - 2018-05-08
CVE-2017-2599 CloudBees Jenkins 安全漏洞 CWE-863 4.3 - 2018-04-11

All 146 known CVE vulnerabilities affecting Jenkins with full Chinese analysis, references, and POCs where available.