Total vulnerabilities in the database
A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initialization. There is a very short window of time after startup during which Jenkins may no longer show the 'Please wait while Jenkins is getting ready to work' message but Cross-Site Request Forgery (CSRF) protection may not yet be effective.
Software | From | Fixed in |
---|---|---|
jenkins / jenkins | - | 2.89.1.x |
jenkins / jenkins | - | 2.94.x |
![]() |
2.81 | 2.89.2 |
![]() |
2.90 | 2.95 |