×
Jan 24, 2024 · This advisory announces vulnerabilities in the following Jenkins deliverables: Jenkins (core); Git server Plugin · GitLab Branch Source ...
Security advisories are the primary way to publicly inform Jenkins users about security issues in Jenkins and Jenkins plugins. You can find all past security ...
2018 · Jenkins Security Advisory 2018-12-05. Affects Jenkins Core · Jenkins Security Advisory 2018-10-29 · Jenkins Security Advisory 2018-10-10 · Jenkins ...
Implementation. The CSP header sent by Jenkins can be modified by setting the Java system property hudson.model.DirectoryBrowserSupport.CSP : If its value is ...
The "Security" section of the web UI allows a Jenkins administrator to enable, configure, or disable key security features which apply to the entire Jenkins ...
May 16, 2023 · This vulnerability allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials. LDAP Plugin 676.
Apr 16, 2024 · Allows Jenkins administrators to control what in-process scripts can be run by less-privileged users.
Apr 30, 2024 · Add the ability to test your code dependencies for vulnerabilities against Snyk database.
Jul 12, 2023 · This vulnerability allows attackers to have Jenkins connect to an attacker-specified URL, capturing a newly generated JCLI token that allows ...
Oct 25, 2023 · This allows attackers with Overall/Read permission to enumerate credentials IDs of LAMBDATEST credentials stored in Jenkins.