Skip to content
COOEY

FAIL › dossier

Jenkins

VENDOR

· dossier confidence 90%

Jenkins, a popular CI/CD automation server, has a history of critical security vulnerabilities, including remote code execution and information disclosure, with recent vulnerabilities actively exploited in ransomware attacks. This poses a significant risk to software development workflows and requires immediate attention.

PROFILE
Categorydeveloper toolsWhat they doJenkins is an open-source automation server for building, testing, and deploying software, widely used in CI/CD pipelines. It facilitates application development, testing, and deployment.Founded2011Size300K+ installations usersOwnershippublic Websitehttps://hiltonsoftware.co/tools/jenkins ↗
SECURITY POSTURE

Jenkins has a history of critical remote code execution vulnerabilities, indicating a significant risk profile. Exploits for recent vulnerabilities have been disclosed and actively used in ransomware attacks.

Notable failures
  • CVE-2024-23897 (critical RCE) - ransomware attacks
  • CVE-2017-1000353 (high RCE) - remote code execution vulnerability
  • CVE-2019-1003030 (high RCE) - sandbox escape
  • CVE-2018-1000861 (high RCE) - code execution vulnerability
  • CVE-2015-5317 (high) - information disclosure vulnerability
  • CVE-2019-1003029 (high) - sandbox bypass
Patterns: repeated critical RCE vulnerabilities; vulnerabilities in plugins; information disclosure vulnerabilities
FAILURE HISTORY · 7
DATEEVENTSEVSUMMARY
2024-08-19 CVE-2024-23897 critical A path traversal flaw in Jenkins CLI allowed attackers to read files and execute code, leading to ransomware attacks.
2022-04-25 CVE-2019-1003029 high An attacker bypassed the Jenkins Script Security Plugin sandbox, enabling arbitrary code execution in Jenkins pipelines.
2022-03-25 CVE-2019-1003030 high The Jenkins Matrix Project Plugin contained an unpatched remote code execution vulnerability that allowed sandbox escape and arbitrary code execution.
2022-02-10 CVE-2018-1000861 high Jenkins Stapler Web Framework suffered a deserialization of untrusted data vulnerability allowing remote code execution.
2025-10-02 CVE-2017-1000353 high Jenkins RCE flaw exploited in wild
2025-10-02 CVE-2017-1000353 high Jenkins RCE flaw exploited in wild
2023-05-12 CVE-2015-5317 high Jenkins UI info disclosure vulnerability exposed sensitive data.
Open questions: What is the ownership structure of Jenkins? · What is the headquarters location of Jenkins? · What is the current security posture of Jenkins and what steps are being taken to address the identified vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-21 06:13:28.774545+00:00