Jenkins-ci
5 CVEs tracked since 2013. Since Nov 2013, none of them reached CISA KEV.
Jenkins-ci CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2013-11 | 2 | 0 |
| 2013-12 | null or fewer | |
| 2014-01 | null or fewer | |
| 2014-02 | null or fewer | |
| 2014-03 | null or fewer | |
| 2014-04 | null or fewer | |
| 2014-05 | 1 | 0 |
| 2014-06 | null or fewer | |
| 2014-07 | null or fewer | |
| 2014-08 | null or fewer | |
| 2014-09 | null or fewer | |
| 2014-10 | 2 | 0 |
Products
The products that kept showing up in Jenkins-ci's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 5 most recently published vulnerabilities affecting Jenkins-ci.
- CVE-2014-3679The Monitoring plugin before 1.53.0 for Jenkins allows remote attackers to obtain sensitive information by accessing unspecified pages.5.0
- CVE-2014-3678Cross-site scripting (XSS) vulnerability in the Monitoring plugin before 1.53.0 for Jenkins allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.4.3
- CVE-2013-6372The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obtain passwords and SSH private keys by reading a subversion.credentials file.2.1
- CVE-2013-6373The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.5.5
- CVE-2013-6374Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.3.5
The record
- Peak rank
- #51 in Nov 2013
- Busiest month shown
- Nov 2013, 2 CVEs
- Months with a KEV entry
- 0 since Nov 2013
- Monthly snapshots
- 3 since 2013