Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bearychat HIGH 8.8
CVE-2023-24458

A cross-site request forgery (CSRF) vulnerability in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified …

Fix: after 3.0.2
Fix from $1,950 2023-01-26
Keycloak Authentication MEDIUM 6.5
CVE-2023-24457

A cross-site request forgery (CSRF) vulnerability in Jenkins Keycloak Authentication Plugin 2.3.0 and earlier allows attackers to trick users into lo…

Fix: after 2.3.0
Fix from $1,600 2023-01-26
Bearychat MEDIUM 6.5
CVE-2023-24459

A missing permission check in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec…

Fix: after 3.0.2
Fix from $1,600 2023-01-26
Testcomplete Support CRITICAL 9.8
CVE-2023-24443

Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2.8.1
Fix from $2,300 2023-01-26
Openid CRITICAL 9.8
CVE-2023-24444

Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login.

Fix: after 2.4
Fix from $2,300 2023-01-26
Keycloak Authentication CRITICAL 9.8
CVE-2023-24456

Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login.

Fix: after 2.3.0
Fix from $2,300 2023-01-26
Openid HIGH 8.8
CVE-2023-24446

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to trick users into logging in to the att…

Fix: after 2.4
Fix from $1,950 2023-01-26
Rabbitmq Consumer HIGH 8.8
CVE-2023-24447

A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers to connect to an attacker-spec…

Fix: after 2.8
Fix from $1,950 2023-01-26
Testquality Updater HIGH 8.8
CVE-2023-24452

A cross-site request forgery (CSRF) vulnerability in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers to connect to an attacker-sp…

Fix: after 1.3
Fix from $1,950 2023-01-26
Rabbitmq Consumer MEDIUM 6.5
CVE-2023-24448

A missing permission check in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers with Overall/Read permission to connect to an attacke…

Fix: after 2.8
Fix from $1,600 2023-01-26
View Cloner MEDIUM 6.5
CVE-2023-24450

Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by…

Mitigation only
Fix from $1,600 2023-01-26
Testquality Updater MEDIUM 6.5
CVE-2023-24453

A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifi…

Fix: after 1.3
Fix from $1,600 2023-01-26
Openid MEDIUM 6.1
CVE-2023-24445

Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins.

Fix: after 2.4
Fix from $1,600 2023-01-26
Testquality Updater MEDIUM 5.5
CVE-2023-24454

Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkin…

Fix: after 1.3
Fix from $1,600 2023-01-26
Semantic Versioning CRITICAL 9.8
CVE-2023-24429

Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitatio…

Fix: 1.15+
Fix from $2,300 2023-01-26
Semantic Versioning CRITICAL 9.8
CVE-2023-24430

Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: 1.15+
Fix from $2,300 2023-01-26
Mstest CRITICAL 9.8
CVE-2023-24441

Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.0.0
Fix from $2,300 2023-01-26
Orka By Macstadium HIGH 8.8
CVE-2023-24432

A cross-site request forgery (CSRF) vulnerability in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers to connect to an attacker-sp…

Fix: 1.32+
Fix from $1,950 2023-01-26
Github Pull Request Builder HIGH 8.8
CVE-2023-24434

A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers to connect to an …

Fix: after 1.42.2
Fix from $1,950 2023-01-26
Jira Pipeline Steps HIGH 8.8
CVE-2023-24437

A cross-site request forgery (CSRF) vulnerability in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers to connect…

Fix: after 2.0.165.v8846cf59f3db
Fix from $1,950 2023-01-26
Orka By Macstadium MEDIUM 6.5
CVE-2023-24433

Missing permission checks in Jenkins Orka by MacStadium Plugin 1.31 and earlier allow attackers with Overall/Read permission to connect to an attacke…

Fix: 1.32+
Fix from $1,600 2023-01-26
Github Pull Request Builder MEDIUM 6.5
CVE-2023-24435

A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to connect …

Fix: after 1.42.2
Fix from $1,600 2023-01-26
Jira Pipeline Steps MEDIUM 6.5
CVE-2023-24438

A missing permission check in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers with Overall/Read permission to c…

Fix: after 2.0.165.v8846cf59f3db
Fix from $1,600 2023-01-26
Bitbucket Oauth MEDIUM 5.7
CVE-2023-24428

A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in …

Fix: 0.13+
Fix from $1,600 2023-01-26
Jira Pipeline Steps MEDIUM 5.5
CVE-2023-24439

Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file on the Jenk…

Fix: after 2.0.165.v8846cf59f3db
Fix from $1,600 2023-01-26
Jira Pipeline Steps MEDIUM 5.5
CVE-2023-24440

Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configurat…

Fix: after 2.0.165.v8846cf59f3db
Fix from $1,600 2023-01-26
Github Pull Request Coverage Status MEDIUM 5.5
CVE-2023-24442

Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password u…

Fix: after 2.2.0
Fix from $1,600 2023-01-26
Bitbucket Oauth CRITICAL 9.8
CVE-2023-24427

Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.

Fix: after 0.13
Fix from $2,300 2023-01-26
Script Security HIGH 8.8
CVE-2023-24422

A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with pe…

Fix: 1229.v4880b_b_e905a_6+
Fix from $1,950 2023-01-26
Openid Connect Authentication HIGH 8.8
CVE-2023-24424

Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login.

Fix: 2.5+
Fix from $1,950 2023-01-26