Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-2481

NIXPKGS-2026-2481
published 1 week, 3 days ago
jenkins: security issues < 2.568.3
Permalink CVE-2026-84645
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 1 week, 3 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects …

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution.

References

Affected products

Jenkins
  • <2.568.*
  • *

Matching in nixpkgs

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Permalink CVE-2026-84649
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 1 week, 3 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included …

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for the targeted user's session and perform actions on their behalf.

References

Affected products

Jenkins
  • <2.568.*
  • *
  • <2.447

Matching in nixpkgs

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Permalink CVE-2026-84646
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 1 week, 3 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user …

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.

References

Affected products

Jenkins
  • <2.568.*
  • *

Matching in nixpkgs

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Permalink CVE-2026-84651
6.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 1 week, 3 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the …

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers with Agent/Configure permission on one agent to take over a different agent, gaining control of its configuration and obtaining access to its inbound agent secret and environment variables.

References

Affected products

Jenkins
  • <2.568.*
  • *

Matching in nixpkgs

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Permalink CVE-2026-84657
4.2 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 1 week, 3 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the …

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users.

References

Affected products

Jenkins
  • <2.568.*
  • *

Matching in nixpkgs

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Permalink CVE-2026-84650
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 1 week, 3 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient …

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.

References

Affected products

Jenkins
  • <2.568.*
  • *

Matching in nixpkgs

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Permalink CVE-2026-84655
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 1 week, 3 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not …

Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.

References

Affected products

Jenkins
  • <2.568.*
  • *

Matching in nixpkgs

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Permalink CVE-2026-84647
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 1 week, 3 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins …

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended.

References

Affected products

Jenkins
  • <2.568.*
  • *

Matching in nixpkgs

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Permalink CVE-2026-84656
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 1 week, 3 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
A missing permission check in Jenkins 2.579 and earlier, LTS …

A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to.

References

Affected products

Jenkins
  • <2.568.*
  • *

Matching in nixpkgs

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

updated 1 week, 3 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins …

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the "remember me" cookie, grants the attacker access to Jenkins as that user.

References

Affected products

Jenkins
  • <2.568.*
  • *

Matching in nixpkgs

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Permalink CVE-2026-84648
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 1 week, 3 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the …

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.

References

Affected products

Jenkins
  • <2.568.*
  • *

Matching in nixpkgs

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Permalink CVE-2026-84654
5.4 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 1 week, 3 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins …

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of the bound configuration object, allowing attackers who can submit configuration forms to modify public static fields of the configuration objects those forms are bound to, resulting in changes that apply globally to the Jenkins instance.

References

Affected products

Jenkins
  • <2.568.*
  • *

Matching in nixpkgs

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

updated 1 week, 3 days ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 …

Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.

References

Affected products

Jenkins
  • <2.568.*
  • *
  • <2.421

Matching in nixpkgs

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers