Known Vulnerabilities for Job Configuration History by Jenkins
Listed below are 7 of the newest known vulnerabilities associated with "Job Configuration History" by "Jenkins".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-62387 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS c... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-62386 json | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query para... | Not Provided | 2026-07-17 | 2026-07-23 |
| CVE-2026-58656 json | Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-A... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-57287 json | Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets whe... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-48532 json | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configura... | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-5724 json | The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper an... | Not Provided | 2026-04-10 | 2026-07-08 |
| CVE-2023-41933 json | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML ext... | 8.8 - HIGH | 2023-09-06 | 2023-09-11 |
| CVE-2023-41932 json | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in mu... | 6.5 - MEDIUM | 2023-09-06 | 2023-09-11 |
| CVE-2023-41931 json | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not property sanitize or escape the timestamp v... | 5.4 - MEDIUM | 2023-09-06 | 2023-09-11 |
| CVE-2023-41930 json | Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict the 'name' query parameter when re... | 4.3 - MEDIUM | 2023-09-06 | 2023-09-11 |