Jenkins
Jenkins Github Branch Source: vulnerabilities and CVEs
Jenkins Github Branch Source has 8 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs8
Last 12 months2
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57285 | Medium (4.3) | 0.28% | — | Jun 24, 2026 | A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the… |
| CVE-2026-42522 | Medium (4.3) | 0.28% | — | Apr 29, 2026 | A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub… |
| CVE-2024-23903 | Medium (5.3) | 0.50% | — | Jan 24, 2024 | Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to… |
| CVE-2024-23902 | Medium (4.3) | 0.32% | — | Jan 24, 2024 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier allows attackers to connect to an attacker-specified URL. |
| CVE-2024-23901 | Medium (6.5) | 0.46% | — | Jan 24, 2024 | Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share a project, resulting in a… |
| CVE-2018-1000185 | Medium (4.3) | 0.64% | — | Jun 5, 2018 | A server-side request forgery vulnerability exists in Jenkins GitHub Branch Source Plugin 2.3.4 and older in Endpoint.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a… |
| CVE-2017-1000091 | Medium (6.3) | 0.64% | — | Oct 5, 2017 | GitHub Branch Source Plugin connects to a user-specified GitHub API URL (e.g. GitHub Enterprise) as part of form validation and completion (e.g. to verify Scan Credentials are correct). This functionality improperly… |
| CVE-2017-1000087 | Medium (4.3) | 0.79% | — | Oct 5, 2017 | GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use. This functionality did not check permissions, allowing any user with Overall/Read… |