Nixpkgs security tracker

Login with GitHub

Suggestions search

With package: jenkins

Found 18 matching suggestions

View:
Compact
Detailed
Published
Permalink CVE-2026-53436
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines …

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), allowing attackers to perform phishing attacks.

References

Affected products

Jenkins
  • *
  • <2.555.*

Matching in nixpkgs

pkgs.jenkins

Extendable open source continuous integration server

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

  • nixos-unstable 6.4.4
    • nixpkgs-unstable 6.4.4
    • nixos-unstable-small 6.4.4
  • nixos-26.05 -
    • nixos-26.05-small 6.4.4
    • nixpkgs-26.05-darwin 6.4.4
Published
Permalink CVE-2026-53440
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not …

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.

References

Affected products

Jenkins
  • *
  • <2.555.*

Matching in nixpkgs

pkgs.jenkins

Extendable open source continuous integration server

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

  • nixos-unstable 6.4.4
    • nixpkgs-unstable 6.4.4
    • nixos-unstable-small 6.4.4
  • nixos-26.05 -
    • nixos-26.05-small 6.4.4
    • nixpkgs-26.05-darwin 6.4.4
Published
Permalink CVE-2026-53435
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it …

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.

References

Affected products

Jenkins
  • *
  • <2.555.*

Matching in nixpkgs

pkgs.jenkins

Extendable open source continuous integration server

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

  • nixos-unstable 6.4.4
    • nixpkgs-unstable 6.4.4
    • nixos-unstable-small 6.4.4
  • nixos-26.05 -
    • nixos-26.05-small 6.4.4
    • nixpkgs-26.05-darwin 6.4.4
Published
Permalink CVE-2026-53437
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 2 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • jenkins-job-builder
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines …

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks.

References

Affected products

Jenkins
  • *
  • <2.555.*

Matching in nixpkgs

pkgs.jenkins

Extendable open source continuous integration server

Ignored packages (7)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

  • nixos-unstable 6.4.4
    • nixpkgs-unstable 6.4.4
    • nixos-unstable-small 6.4.4
  • nixos-26.05 -
    • nixos-26.05-small 6.4.4
    • nixpkgs-26.05-darwin 6.4.4
Untriaged
created 5 months ago Activity log
  • Created suggestion
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not …

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.

References

Affected products

Jenkins
  • *
  • <2.541.*

Matching in nixpkgs

pkgs.jenkins

Extendable open source continuous integration server

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Untriaged
created 5 months ago Activity log
  • Created suggestion
Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS …

Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or X-Forwarded-Host HTTP request headers, making it vulnerable to DNS rebinding attacks that allow bypassing origin validation.

References

Affected products

Jenkins
  • *
  • <2.426.3
  • <2.541.*
  • <2.442

Matching in nixpkgs

pkgs.jenkins

Extendable open source continuous integration server

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Published
Permalink CVE-2026-27099
8.0 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    10 packages
    • python314Packages.jenkins-job-builder
    • python313Packages.jenkins-job-builder
    • python312Packages.jenkins-job-builder
    • python314Packages.python-jenkins
    • python313Packages.python-jenkins
    • python312Packages.python-jenkins
    • python312Packages.jenkinsapi
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • jenkins-job-builder
  • @LeSuisse deleted
    3 maintainers
    • @coreyoconnor
    • @earldouglas
    • @NeQuissimus
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 …

Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.

References

Affected products

Jenkins
  • *
  • <2.541.*
  • <2.483

Matching in nixpkgs

pkgs.jenkins

Extendable open source continuous integration server

Ignored packages (10)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Ignored maintainers (1)
Upstream advisory: https://www.jenkins.io/security/advisory/2026-02-18/
Published
Permalink CVE-2026-27100
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 6 months ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    10 packages
    • jenkins-job-builder
    • python312Packages.jenkinsapi
    • python313Packages.jenkinsapi
    • python314Packages.jenkinsapi
    • python312Packages.python-jenkins
    • python313Packages.python-jenkins
    • python314Packages.python-jenkins
    • python312Packages.jenkins-job-builder
    • python313Packages.jenkins-job-builder
    • python314Packages.jenkins-job-builder
  • @LeSuisse deleted
    3 maintainers
    • @coreyoconnor
    • @earldouglas
    • @NeQuissimus
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run …

Jenkins 2.550 and earlier, LTS 2.541.1 and earlier accepts Run Parameter values that refer to builds the user submitting the build does not have access to, allowing attackers with Item/Build and Item/Configure permission to obtain information about the existence of jobs, the existence of builds, and if a specified build exists, its display name.

References

Affected products

Jenkins
  • *
  • <2.541.*

Matching in nixpkgs

pkgs.jenkins

Extendable open source continuous integration server

Ignored packages (10)

pkgs.jenkins-job-builder

Jenkins Job Builder is a system for configuring Jenkins jobs using simple YAML files stored in Git

Package maintainers

Ignored maintainers (1)
Upstream advisory: https://www.jenkins.io/security/advisory/2026-02-18/