CloudBees maintains Jenkins and Jenkins Operations Center, widely deployed continuous integration and automation platforms that serve as orchestration hubs in DevOps toolchains. The vendor's vulnerability profile reflects the web-facing, credential-handling, and plugin-integration demands of these platforms, with recurring weaknesses centered on cross-site scripting, input validation, cross-site request forgery, and improper credential storage. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cloudbees over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11350CRITICAL CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the proxy configuration page. | Apr 19, 2019 | 9.8 | 30 | NO | NO |
CVE-2012-0785HIGH Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 | Feb 24, 2020 | 7.5 | 26 | NO | NO |
CVE-2012-6073MEDIUM Open redirect vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.46 | Feb 24, 2013 | 5.8 | 20 | NO | NO |
CVE-2013-2034MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allow | May 14, 2014 | 6.8 | 18 | NO | NO |
CVE-2012-6072MEDIUM CRLF injection vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.4 | Feb 24, 2013 | 4.3 | 18 | NO | NO |
Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attach | Feb 24, 2013 | 2.6 | 17 | NO | NO |
Cross-site scripting (XSS) vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466. | Feb 24, 2013 | 3.5 | 16 | NO | NO |
CVE-2012-0325MEDIUM Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows r | Mar 9, 2012 | 4.3 | 16 | NO | NO |
CVE-2012-0324MEDIUM Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows r | Mar 9, 2012 | 4.3 | 16 | NO | NO |
Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allows remote authentica | Apr 10, 2014 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cloudbees.
Media articles that mention a CVE ID that affects a product developed by Cloudbees — matched by CVE ID, not by vendor name.