Jenkins
56 known vulnerabilities
Top Products
Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, incre
Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins co
Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validatio
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar a
Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting
Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-prov
Frequently Asked Questions
How many CVEs affect Jenkins?
Jenkins has 56 CVE records in our database, including 1 critical and 13 high severity vulnerabilities.
What are the most severe Jenkins vulnerabilities?
Jenkins has 1 critical severity (CVSS 9.0+) and 13 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Jenkins vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Jenkins products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Jenkins Vulnerabilities
CyberStrike scans your infrastructure for Jenkins vulnerabilities and provides real-time remediation guidance.
Get Started