Exposure of Jenkins

CI
37
exposure score
13
sites use
1
exploited
3
critical
Vexday analysis

Jenkins acumula 141 CVEs catalogadas, com 8 novas surgidas nos últimos 90 dias, indicando um fluxo contínuo de descobertas que exige acompanhamento ativo. A taxa de exploração ativa está acima da média geral do catálogo — 1,6× superior —, e a CVE mais perigosa em atividade, CVE-2024-23897, registra EPSS máximo de 1,0, sinalizando probabilidade praticamente certa de exploração em ambientes expostos. O tipo de falha mais recorrente é CWE-862 (ausência de verificação de autorização), uma classe de vulnerabilidade que tende a viabilizar acesso não autorizado a funcionalidades críticas em ambientes de CI/CD. Equipes que operam Jenkins devem priorizar a correção das CVEs críticas e verificar imediatamente a exposição à CVE-2024-23897, dado o risco concreto e imediato que ela representa.

CVEs

159 results
CVE-2025-59475MEDIUMJenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profile dropdown menu, allEPSS 0.5%CVE-2026-27099HIGHJenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of EPSS 0.5%CVE-2026-84652HIGHIn Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember meEPSS 0.5%CVE-2026-53437MEDIUMJenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to JenkinsEPSS 0.5%CVE-2026-84648HIGHIn Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestaEPSS 0.4%CVE-2025-27624MEDIUMA cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users togglEPSS 0.4%CVE-2026-84647HIGHIn Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier,EPSS 0.4%CVE-2025-31720MEDIUMA missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but withouEPSS 0.4%CVE-2025-31721MEDIUMA missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but withouEPSS 0.4%CVE-2025-59476MEDIUMJenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted from user-specified coEPSS 0.4%CVE-2026-84650HIGHIn Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to EPSS 0.4%CVE-2026-27100MEDIUMJenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not EPSS 0.3%CVE-2025-27623MEDIUMJenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via RESTEPSS 0.3%CVE-2026-70427MEDIUMJenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction EPSS 0.3%CVE-2026-70428MEDIUMJenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowEPSS 0.3%CVE-2026-70426CRITICALIn Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, EPSS 0.3%CVE-2026-53436MEDIUMJenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to JenkinsEPSS 0.3%CVE-2026-84646MEDIUMIn Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allEPSS 0.3%CVE-2026-33002HIGHJenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made tEPSS 0.3%CVE-2026-84653LOWJenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in tEPSS 0.3%