Exposição de Jenkins

CI
37
score de exposição
13
sites usam
1
em exploração
3
críticos
Análise Vexday

Jenkins acumula 141 CVEs catalogadas, com 8 novas surgidas nos últimos 90 dias, indicando um fluxo contínuo de descobertas que exige acompanhamento ativo. A taxa de exploração ativa está acima da média geral do catálogo — 1,6× superior —, e a CVE mais perigosa em atividade, CVE-2024-23897, registra EPSS máximo de 1,0, sinalizando probabilidade praticamente certa de exploração em ambientes expostos. O tipo de falha mais recorrente é CWE-862 (ausência de verificação de autorização), uma classe de vulnerabilidade que tende a viabilizar acesso não autorizado a funcionalidades críticas em ambientes de CI/CD. Equipes que operam Jenkins devem priorizar a correção das CVEs críticas e verificar imediatamente a exposição à CVE-2024-23897, dado o risco concreto e imediato que ela representa.

CVEs

159 resultados
CVE-2026-53441MEDIUMJenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of EPSS 0.3%CVE-2026-84651MEDIUMIn Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submEPSS 0.2%CVE-2025-67636MEDIUMA missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypteEPSS 0.2%CVE-2023-27903MEDIUMJenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions EPSS 0.2%CVE-2026-70429HIGHJenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackeEPSS 0.2%CVE-2023-27899HIGHJenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions EPSS 0.2%CVE-2026-53440MEDIUMJenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" securityEPSS 0.2%CVE-2026-53439MEDIUMMissing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine otEPSS 0.2%CVE-2026-84655MEDIUMJenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST APIEPSS 0.2%CVE-2026-53438MEDIUMA missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking IEPSS 0.2%CVE-2026-84654MEDIUMIn Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier,EPSS 0.2%CVE-2026-70430LOWJenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naEPSS 0.2%CVE-2026-84656MEDIUMA missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one EPSS 0.2%CVE-2025-67639LOWA cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users intoEPSS 0.2%CVE-2026-84657MEDIUMIn Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flaEPSS 0.2%CVE-2026-53442MEDIUMJenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job confEPSS 0.2%CVE-2025-67637MEDIUMJenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins contEPSS 0.2%CVE-2026-84649HIGHIn Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 thEPSS 0.2%CVE-2025-67638MEDIUMJenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasEPSS 0.2%