Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Azure Ad HIGH 8.8
CVE-2023-24426

Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login.

Fix: after 303.va_91ef20ee49f
Fix from $1,950 2023-01-26
Gerrit Trigger MEDIUM 6.5
CVE-2023-24423

A cross-site request forgery (CSRF) vulnerability in Jenkins Gerrit Trigger Plugin 2.38.0 and earlier allows attackers to rebuild previous builds tri…

Fix: 2.38.1+
Fix from $1,600 2023-01-26
Kubernetes Credentials Provider MEDIUM 6.5
CVE-2023-24425

Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup…

Fix: after 1.208.v128ee9800c04
Fix from $1,600 2023-01-26
Sonar Gerrit MEDIUM 6.5
CVE-2022-46688

A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins conne…

Fix: after 377.v8f3808963dc5
Fix from $1,600 2022-12-12
Checkmarx MEDIUM 5.4
CVE-2022-46684

Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTML reports,…

Fix: 2022.4.3+
Fix from $1,600 2022-12-12
Custom Build Properties MEDIUM 5.4
CVE-2022-46686

Jenkins Custom Build Properties Plugin 2.79.vc095ccc85094 and earlier does not escape property values and build display names on the Custom Build Pro…

Fix: after 2.79.vc095ccc85094
Fix from $1,600 2022-12-12
Spring Config MEDIUM 5.4
CVE-2022-46687

Jenkins Spring Config Plugin 2.0.0 and earlier does not escape build display names shown on the Spring Config view, resulting in a stored cross-site …

Fix: 2.0.1+
Fix from $1,600 2022-12-12
Plot CRITICAL 9.8
CVE-2022-46682

Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: 2.1.12+
Fix from $2,300 2022-12-12
Google Login MEDIUM 6.1
CVE-2022-46683

Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkin…

Fix: 1.7+
Fix from $1,600 2022-12-12
Associated Files MEDIUM 5.4
CVE-2022-45401

Jenkins Associated Files Plugin 0.2.1 and earlier does not escape names of associated files, resulting in a stored cross-site scripting (XSS) vulnera…

Fix: after 0.2.1
Fix from $1,600 2022-11-15
Osf Builder Suite \ CRITICAL 9.8
CVE-2022-45397

Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.0.2
Fix from $2,300 2022-11-15
Japex CRITICAL 9.8
CVE-2022-45400

Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.7
Fix from $2,300 2022-11-15
Cccc CRITICAL 9.8
CVE-2022-45395

Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.6
Fix from $2,300 2022-11-15
Sourcemonitor CRITICAL 9.8
CVE-2022-45396

Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.2
Fix from $2,300 2022-11-15
Config Rotator HIGH 7.5
CVE-2022-45388

Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers…

Fix: after 2.0.1
Fix from $1,950 2022-11-15
Ns Nd Integration Performance Publisher HIGH 7.5
CVE-2022-45391

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname v…

Fix: 4.8.0.146+
Fix from $1,950 2022-11-15
Ns Nd Integration Performance Publisher MEDIUM 6.5
CVE-2022-45392

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins cont…

Fix: 4.8.0.146+
Fix from $1,600 2022-11-15
Bart MEDIUM 5.4
CVE-2022-45387

Jenkins BART Plugin 1.0.3 and earlier does not escape the parsed content of build logs before rendering it on the Jenkins UI, resulting in a stored c…

Fix: after 1.0.3
Fix from $1,600 2022-11-15
Xp Dev MEDIUM 5.3
CVE-2022-45389

A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an at…

Fix: after 1.0
Fix from $1,600 2022-11-15
Pipeline Utility Steps HIGH 8.1
CVE-2022-45381

Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of Apache Com…

Fix: 2.13.2+
Fix from $1,950 2022-11-15
Ns Nd Integration Performance Publisher HIGH 7.5
CVE-2022-38666

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for…

Fix: after 4.8.0.146
Fix from $1,950 2022-11-15
Script Security HIGH 7.5
CVE-2022-45379

Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable …

Fix: 1190.v65867a_a_47126+
Fix from $1,950 2022-11-15
Cloudbees Docker Hub\/registry Notification HIGH 7.5
CVE-2022-45385

A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger…

Fix: 2.6.2.1+
Fix from $1,950 2022-11-15
Support Core MEDIUM 6.5
CVE-2022-45383

An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission…

Fix: 1206.1208.v9b_7a_1d48db_0f+
Fix from $1,600 2022-11-15
Reverse Proxy Auth MEDIUM 6.5
CVE-2022-45384

Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins control…

Fix: 1.7.4+
Fix from $1,600 2022-11-15
Violations MEDIUM 5.5
CVE-2022-45386

Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.7.11
Fix from $1,600 2022-11-15
Junit MEDIUM 5.4
CVE-2022-45380

Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in…

Fix: 1160.vf1f01a_a_ea_b_7f+
Fix from $1,600 2022-11-15
Naginator MEDIUM 5.4
CVE-2022-45382

Jenkins Naginator Plugin 1.18.1 and earlier does not escape display names of source builds in builds that were triggered via Retry action, resulting …

Fix: 1.18.2+
Fix from $1,600 2022-11-15
Neuvector Vulnerability Scanner MEDIUM 5.3
CVE-2022-43434

Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protection for user-generated conte…

Fix: after 1.20
Fix from $1,600 2022-10-19
360 Fireline MEDIUM 5.3
CVE-2022-43435

Jenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, …

Fix: after 1.7.2
Fix from $1,600 2022-10-19