Jenkins is an open-source automation server whose vulnerability profile is shaped by its role as a widely deployed pipeline and CI/CD orchestration platform, with a large footprint spanning the core Jenkins server, plugin ecosystem (including Pipeline and Script Security), and integrations such as Active Directory authentication. The vendor's exposure recurs through application-layer weakness classes including cross-site scripting, cross-site request forgery, missing authorization checks, and insufficiently protected credentials—flaws characteristic of web-facing automation systems that interact with sensitive build artifacts and infrastructure secrets. A meaningful share of the vendor's disclosures reach serious severity, reflecting the elevated privilege and access scope that Jenkins often holds within development and deployment environments. Defenders should treat Jenkins deployments as trust-critical infrastructure, prioritize network isolation and access controls, and maintain close tracking of plugin updates alongside core server patches, since the extensible architecture means that third-party plugins frequently introduce new exposure vectors. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jenkins Project over time
Of all the CVEs published by Jenkins Project as a CNA, 98.3% affect products that Jenkins Project develops as a vendor.
Of all the CVEs published that affect products developed by Jenkins Project, 82.9% are self-published by Jenkins Project as a CNA.
Signals from CVEs in this vendor scope (1798 CVEs).
1,798 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23897CRITICAL Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with t | Jan 24, 2024 | 9.8 | 99 | YES | YES |
CVE-2017-1000353CRITICAL Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerabili | Jan 29, 2018 | 9.8 | 99 | YES | YES |
CVE-2018-1000861CRITICAL A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/Meta | Dec 10, 2018 | 9.8 | 98 | YES | YES |
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2019-1003030CRITICAL A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allo | Mar 8, 2019 | 9.9 | 96 | YES | YES |
CVE-2019-1003029CRITICAL A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, sr | Mar 8, 2019 | 9.9 | 96 | YES | YES |
CVE-2019-1003000HIGH A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows | Jan 22, 2019 | 8.8 | 93 | NO | YES |
CVE-2016-9299CRITICAL The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP quer | Jan 12, 2017 | 9.8 | 93 | NO | YES |
CVE-2015-8103CRITICAL The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a proble | Nov 25, 2015 | 9.8 | 90 | NO | YES |
CVE-2016-0792HIGH Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, rel | Apr 7, 2016 | 8.8 | 88 | NO | YES |
Signals from CVEs in this vendor scope (1798 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jenkins Project.
Media articles that mention a CVE ID that affects a product developed by Jenkins Project — matched by CVE ID, not by vendor name.