Skip to content

Jenkins

Pipelines

Jenkins automation server

Java Latest jenkins-2.574 · 5d ago Security brief →

Features

  • Open‑source automation server for building, testing and deploying software
  • Supports over 2,000 plugins to extend functionality
  • Provides Docker images, WAR files and native packages

Security Response History

5 CVEs
CVE Severity Disclosed Patched (this tool) vs Ecosystem Median
CVE-2017-1000353 KEV critical
CVSS 9.8
2025-10-02 2026-01-06 3mo / median 3mo
CVE-2024-23897 KEV critical
CVSS 9.8
2024-08-19 2026-01-06 1y 5mo / median 1y 5mo
CVE-2015-5317 KEV high
CVSS 7.5
2023-05-12 2026-01-06 2y 8mo / median 2y 8mo
CVE-2021-39144 KEV high
CVSS 8.5
2023-03-10 2026-01-06 2y 10mo / median 2y 10mo
CVE-2018-1000861 KEV critical
CVSS 9.8
2022-02-10 2026-01-06 3y 11mo / median 3y 11mo

Recent releases

View all 35 releases →
No immediate action
jenkins-2.574 Mixed

NPE fix + Spanish clarification + token config

No immediate action
jenkins-2.568.1 Breaking risk

Breaking changes — review before upgrading.

Review required
jenkins-2.572 Mixed
RCE / SSRF

Password rules + UI refinements

No immediate action
jenkins-2.571 Bug fix

Animation artifact fix

No immediate action
jenkins-2.570 Mixed

SSH key search + UI fixes + Korean translation

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
25,587
Forks
9,613
Languages
Java HTML JavaScript

Install & Platforms

Install via
docker binary
Platforms
linux windows

Community & Support

Beta — feedback welcome: [email protected]