PatchSiren

Jenkins Project CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Jenkins Project CVE published 2026-05-27

CVE-2026-48925

A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to trigger a build for a pull request. The vulnerability was published on 2026-05-27 and carries a CVSS 3.1 score of 4.3 (MEDIUM severity). The issue stems from missing CSRF protections on an endpoint that initiates pull request builds, enabling an attacker to forge requests that could [truncated]

MEDIUM Jenkins Project CVE published 2026-05-27

CVE-2026-48924

Jenkins Bitbucket OAuth Plugin 0.17 and earlier contains an open redirect vulnerability (CWE-601) that allows attackers to redirect users to arbitrary URLs after authentication. The plugin fails to validate or restrict the redirect URL parameter during the OAuth login flow, enabling phishing attacks where users may be sent to attacker-controlled sites after completing legitimate authentication. This vulne [truncated]

MEDIUM Jenkins Project CVE published 2026-05-27

CVE-2026-48923

A missing permission check in the Jenkins AppSpider Plugin (versions 1.0.17 and earlier) allows attackers with Overall/Read permission to connect to attacker-specified URLs through a form validation method. This vulnerability, disclosed in the Jenkins security advisory for May 27, 2026, enables unauthorized Server-Side Request Forgery (SSRF) capabilities that could be leveraged for internal network reconn [truncated]

HIGH Jenkins Project CVE published 2026-05-27

CVE-2026-48922

A path traversal vulnerability in Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier allows attackers with job credential configuration privileges to write files to arbitrary locations on the Jenkins node filesystem. The vulnerability stems from improper sanitization of file names for file and zip file credentials. Successful exploitation can lead to remote code execution when Jenkins is co [truncated]

HIGH Jenkins Project CVE published 2026-05-27

CVE-2026-48921

A path traversal vulnerability in Jenkins Pipeline: Groovy Libraries Plugin allows attackers with control over shared library content to read arbitrary files on the Jenkins controller filesystem. The plugin versions 797.v90ea_a_9b_e45a_0 and earlier fail to prohibit symbolic links in shared libraries, enabling directory traversal attacks. This vulnerability is classified as HIGH severity with a CVSS score [truncated]

HIGH Jenkins Project CVE published 2026-05-27

CVE-2026-48920

Jenkins Email Extension Plugin 1933.v45cec755423f and earlier contains a path traversal vulnerability (CWE-73) that allows attackers with control over email content to read arbitrary files from the Jenkins controller filesystem. The plugin permits inlining images as base64 via the `data-inline` attribute without restricting the image URLs that can be inlined, enabling attackers to specify `file:` URLs to [truncated]

MEDIUM Jenkins Project CVE published 2026-05-27

CVE-2026-48919

The Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation, creating a deserialization of untrusted data vulnerability (CWE-502). This flaw could allow an attacker with administrative privileges to execute arbitrary code through malicious LDAP referral responses. The vulnerability was disclosed in the Jenkins security advisory dated 2026-05-27. The CVSS 3 [truncated]

MEDIUM Jenkins Project CVE published 2026-05-27

CVE-2026-48918

The Jenkins Active Directory Plugin versions 2.41 and earlier follow LDAP referrals by default, which may allow authentication requests to be redirected to unintended directory servers. This behavior could potentially enable Server-Side Request Forgery (SSRF) or credential disclosure scenarios if an attacker can influence referral targets in a compromised or maliciously configured Active Directory environ [truncated]

MEDIUM Jenkins Project CVE published 2026-05-27

CVE-2026-48917

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation. This vulnerability allows an attacker to potentially execute arbitrary code through maliciously crafted LDAP referral responses. The issue stems from improper deserialization of untrusted data (CWE-502), a common attack vector in Java applications. The vulnerability was disclosed in the Jenkins secu [truncated]

MEDIUM Jenkins Project CVE published 2026-05-27

CVE-2026-48916

The Jenkins LDAP Plugin versions 807.v7d7de30930cf and earlier follow LDAP referrals, which can lead to Server-Side Request Forgery (SSRF) conditions. When the plugin processes LDAP referrals, it may make outbound connections to attacker-controlled servers specified in malicious referral responses. This behavior is classified under CWE-918 (Server-Side Request Forgery). The vulnerability requires high att [truncated]

HIGH Jenkins Project CVE published 2026-03-18

CVE-2026-33001

CVE-2026-33001 is a high-severity vulnerability in Jenkins that allows attackers to write files to arbitrary locations on the filesystem using crafted .tar and .tar.gz archives. This vulnerability affects Jenkins versions 2.554 and earlier, as well as LTS versions 2.541.2 and earlier. An attacker with Item/Configure permission or control over agent processes can exploit this vulnerability to deploy malici [truncated]

Review Jenkins project CVE published 2019-01-22

CVE-2019-1003000

CVE-2019-1003000 describes a sandbox bypass in Jenkins Script Security Plugin 1.49 and earlier. If an attacker can provide sandboxed scripts, the flaw may let them escape the intended restrictions and execute arbitrary code on the Jenkins master JVM. Because the controller/master is central to Jenkins operations, this is a high-impact issue for environments that accept or process untrusted Groovy scripts.