Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Katalon HIGH 8.8
CVE-2022-43416

Jenkins Katalon Plugin 1.0.32 and earlier implements an agent/controller message that does not limit where it can be executed and allows invoking Kat…

Fix: 1.0.33+
Fix from $1,950 2022-10-19
Compuware Topaz For Total Test HIGH 7.5
CVE-2022-43429

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, …

Fix: after 2.4.8
Fix from $1,950 2022-10-19
Compuware Topaz For Total Test HIGH 7.5
CVE-2022-43430

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2.4.8
Fix from $1,950 2022-10-19
Katalon MEDIUM 6.5
CVE-2022-43419

Jenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by u…

Fix: 1.0.33+
Fix from $1,600 2022-10-19
Contrast Continuous Application Security MEDIUM 5.4
CVE-2022-43420

Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a rep…

Fix: 3.10+
Fix from $1,600 2022-10-19
Custom Checkbox Parameter MEDIUM 5.4
CVE-2022-43425

Jenkins Custom Checkbox Parameter Plugin 1.4 and earlier does not escape the name and description of Custom Checkbox Parameter parameters on views di…

Fix: after 1.4
Fix from $1,600 2022-10-19
Tuleap Git Branch Source MEDIUM 5.3
CVE-2022-43421

A missing permission check in Jenkins Tuleap Git Branch Source Plugin 3.2.4 and earlier allows unauthenticated attackers to trigger Tuleap projects w…

Fix: 3.2.5+
Fix from $1,600 2022-10-19
Compuware Topaz Utilities MEDIUM 5.3
CVE-2022-43422

Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier implements an agent/controller message that does not limit where it can be executed, allow…

Fix: 1.0.9+
Fix from $1,600 2022-10-19
Compuware Source Code Download For Endevor\, Pds\, And Ispw MEDIUM 5.3
CVE-2022-43423

Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier implements an agent/controller message that does not limi…

Fix: 2.0.13+
Fix from $1,600 2022-10-19
Compuware Xpediter Code Coverage MEDIUM 5.3
CVE-2022-43424

Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can be executed…

Fix: 1.0.8+
Fix from $1,600 2022-10-19
S3 Explorer MEDIUM 5.3
CVE-2022-43426

Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potential for attackers to observe an…

Fix: after 1.0.8
Fix from $1,600 2022-10-19
Compuware Topaz For Total Test MEDIUM 5.3
CVE-2022-43428

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, …

Fix: after 2.4.8
Fix from $1,600 2022-10-19
Script Security CRITICAL 9.9
CVE-2022-43401

A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Script Security Plugin 1183.v77…

Fix: after 1183.v774b_0b_0a_a_451
Fix from $2,300 2022-10-19
Pipeline\ CRITICAL 9.9
CVE-2022-43402

A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pipeline: Groovy Plugin 2802.v5…

Fix: after 2802.v5ea_628154b_c2
Fix from $2,300 2022-10-19
Script Security CRITICAL 9.9
CVE-2022-43403

A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and ea…

Fix: after 1183.v774b_0b_0a_a_451
Fix from $2,300 2022-10-19
Script Security CRITICAL 9.9
CVE-2022-43404

A sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic constructors in Jenkins Script Security …

Fix: after 1183.v774b_0b_0a_a_451
Fix from $2,300 2022-10-19
Groovy Libraries CRITICAL 9.9
CVE-2022-43405

A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attackers with permission to define…

Fix: after 612.v84da_9c54906d
Fix from $2,300 2022-10-19
Groovy Libraries CRITICAL 9.9
CVE-2022-43406

A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permissio…

Fix: after 583.vf3b_454e43966
Fix from $2,300 2022-10-19
Pipeline\ HIGH 8.8
CVE-2022-43407

Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specified ID of the 'input' step, wh…

Fix: after 451.vf1a_a_4f405289
Fix from $1,950 2022-10-19
Repo HIGH 7.5
CVE-2022-43415

Jenkins REPO Plugin 1.15.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: 1.16.0+
Fix from $1,950 2022-10-19
Pipeline\ MEDIUM 6.5
CVE-2022-43408

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or a…

Fix: 2.27+
Fix from $1,600 2022-10-19
Pipeline\ MEDIUM 5.4
CVE-2022-43409

Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST reques…

Fix: after 838.va_3a_087b_4055b
Fix from $1,600 2022-10-19
Mercurial MEDIUM 5.3
CVE-2022-43410

Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its w…

Fix: after 1251.va_b_121f184902
Fix from $1,600 2022-10-19
GitLab MEDIUM 5.3
CVE-2022-43411

Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token a…

Fix: 1.5.36+
Fix from $1,600 2022-10-19
Generic Webhook Trigger MEDIUM 5.3
CVE-2022-43412

Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whether the provided and expecte…

Fix: 1.84.2+
Fix from $1,600 2022-10-19
Nunit MEDIUM 5.3
CVE-2022-43414

Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specified directory as test results, …

Fix: 0.28+
Fix from $1,600 2022-10-19
Worksoft Execution Manager HIGH 8.8
CVE-2022-41245

A cross-site request forgery (CSRF) vulnerability in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers to connect to …

Fix: after 10.0.3.503
Fix from $1,950 2022-09-21
Scm Httpclient HIGH 8.8
CVE-2022-41249

A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers to connect to an attacker-specifi…

Fix: after 1.5
Fix from $1,950 2022-09-21
Cons3rt HIGH 8.8
CVE-2022-41253

A cross-site request forgery (CSRF) vulnerability in Jenkins CONS3RT Plugin 1.0.0 and earlier allows attackers to connect to an attacker-specified HT…

Fix: after 1.0.0
Fix from $1,950 2022-09-21
View26 Test Reporting HIGH 8.1
CVE-2022-41244

Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the configured View26 server that coul…

Fix: after 1.0.7
Fix from $1,950 2022-09-21