Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cloudbees

First CVE: Mar 9, 2012Active for: 14 yearsTotal CVEs: 10
17.2
VTI Score
Low

CloudBees maintains Jenkins and Jenkins Operations Center, widely deployed continuous integration and automation platforms that serve as orchestration hubs in DevOps toolchains. The vendor's vulnerability profile reflects the web-facing, credential-handling, and plugin-integration demands of these platforms, with recurring weaknesses centered on cross-site scripting, input validation, cross-site request forgery, and improper credential storage. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.1
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cloudbees over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 9, 2012
14 years ago
Most Recent CVE
Feb 24, 2020
2,342 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-11350CRITICAL
CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the proxy configuration page.
Apr 19, 20199.830NONO
CVE-2012-0785HIGH
Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11
Feb 24, 20207.526NONO
CVE-2012-6073MEDIUM
Open redirect vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.46
Feb 24, 20135.820NONO
CVE-2013-2034MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allow
May 14, 20146.818NONO
CVE-2012-6072MEDIUM
CRLF injection vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.4
Feb 24, 20134.318NONO
CVE-2013-0158LOW
Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attach
Feb 24, 20132.617NONO
CVE-2012-6074LOW
Cross-site scripting (XSS) vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.
Feb 24, 20133.516NONO
CVE-2012-0325MEDIUM
Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows r
Mar 9, 20124.316NONO
CVE-2012-0324MEDIUM
Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows r
Mar 9, 20124.316NONO
CVE-2013-2033LOW
Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allows remote authentica
Apr 10, 20142.111NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
30%
50%
10%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network2 (20.0%)
Unknown8 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (20.0%)
High0 (0.0%)
Unknown8 (80.0%)
User Interaction
None2 (20.0%)
Unknown8 (80.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (20.0%)
Unknown8 (80.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cloudbees.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cloudbees — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cloudbees's Products

View all 3 CNAs →

Top CWEs