← All images

jenkins

13 open findings · 12 with upstream fix available

Image: ghcr.io/rtvkiz/minimal-jenkins:latest  ·  Size: 388 MB  ·  Last rebuilt: 0d ago  ·  Updated: 2026-06-17 21:45 UTC

PackageVersionSeverityCVEFixDescriptionVEX
mina-core2.2.4CRITICALGHSA-vf5j-865m-mq7c2.2.7Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41635 Incomplete Fix)
mina-core2.2.4CRITICALGHSA-995c-6rp3-4m4x2.2.7Apache MINA vulnerable to Deserialization of Untrusted Data (CVE-2026-41409 Incomplete Fix)
mina-core2.2.4CRITICALGHSA-8297-v2rf-2p322.2.6Apache MINA vulnerable to Deserialization of Untrusted Data
mina-core2.2.4CRITICALGHSA-f2wh-grmh-r6jm2.2.6Apache MINA Vulnerable to Deserialization of Untrusted Data (CVE-2024-52046 Incomplete Fix)
bcprov-jdk18on1.83HIGHGHSA-p93r-85wp-75v31.84Bouncy Castle Has Covert Timing Channel Vulnerability
bcpg-jdk18on1.83HIGHGHSA-cj8j-37rh-84751.84Bouncy Castle Uncontrolled Resource Consumption vulnerability
jenkins-core2.555.3HIGHGHSA-93qh-vwrm-c5pw2.568Jenkins: Stored XSS vulnerability in node offline cause description
jackson-core3.1.0HIGHGHSA-2m67-wjpj-xhg93.1.1Jackson Core: Document length constraint bypass in blocking, async, and DataInput parsers
commons-lang2.6MEDIUMGHSA-j288-q9x7-2f5vApache Commons Lang is vulnerable to Uncontrolled Recursion when processing long inputs
bcprov-jdk18on1.83MEDIUMGHSA-c3fc-8qff-9hwx1.84Bouncy Castle has an LDAP injection
bcpkix-jdk18on1.83MEDIUMGHSA-wg6q-6289-32hp1.84Bouncy Castle Crypto Package For Java: Use of a Broken or Risky Cryptographic Algorithm vulnerability in bcpkix modules
spring-security-core6.5.9MEDIUMGHSA-x2wq-9x2f-fhj76.5.10Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured
spring-security-core6.5.9LOWGHSA-vxf7-qj7q-83fh6.5.10Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider