All CVEs — page 206 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows authenticated users without roles to access administrative APIs, leading to unauthorized access and potential data manipulation.
The flaw allows attackers with Item/Configure permission to create or replace arbitrary files in the Jenkins controller's file system, leading to potential remote code execution.
The flaw allows attackers to run arbitrary AST transformations, bypassing sandbox protection and executing arbitrary code in the Jenkins controller JVM.