org.jenkins-ci.main:jenkins-core
Maven259 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.main:jenkins-corepage 6 of 6
- CVE-2026-33002HIGHCVSS 7.5EG 7.5✓ Fixed in 2.5552026-03-18
vulnerable: 2.442 ... 2.554 (137 versions)
Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made through the CLI WebSocket endpoint by computing the expected origin for comparison using the Host or…
- CVE-2026-53435HIGHCVSS 8.8EG 8.8✓ Fixed in 2.555.32026-06-10
vulnerable: 1.396 ... 2.99 (1015 versions)
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows the…
- CVE-2026-53436MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.5682026-06-10
vulnerable: 2.556 ... 2.567 (12 versions)
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), allowing attackers to perform phishing at…
- CVE-2026-53437MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.555.32026-06-10
vulnerable: 1.396 ... 2.99 (1015 versions)
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing at…
- CVE-2026-53438MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.555.32026-06-10
vulnerable: 1.396 ... 2.99 (1015 versions)
A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel queue items they do not have permission to view.
- CVE-2026-53439MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.555.32026-06-10
vulnerable: 1.396 ... 2.99 (1015 versions)
Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".
- CVE-2026-53440MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.555.32026-06-10
vulnerable: 1.396 ... 2.99 (1015 versions)
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redire…
- CVE-2026-53441MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.5682026-06-10
vulnerable: 2.483 ... 2.567 (103 versions)
Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored …
- CVE-2026-53442MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.555.32026-06-10
vulnerable: 1.396 ... 2.99 (1015 versions)
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed b…
Check whether org.jenkins-ci.main:jenkins-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.main:jenkins-core CVEs against the assets you own.
Start Free Scan →