Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Worksoft Execution Manager MEDIUM 6.5
CVE-2022-41246

A missing permission check in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers with Overall/Read permission to conne…

Fix: after 10.0.3.503
Fix from $1,600 2022-09-21
Scm Httpclient MEDIUM 6.5
CVE-2022-41250

A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-s…

Fix: after 1.5
Fix from $1,600 2022-09-21
Cons3rt MEDIUM 6.5
CVE-2022-41254

Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specifie…

Fix: after 1.0.0
Fix from $1,600 2022-09-21
Cons3rt MEDIUM 6.5
CVE-2022-41255

Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it can be viewe…

Fix: after 1.0.0
Fix from $1,600 2022-09-21
Bigpanda Notifier MEDIUM 5.3
CVE-2022-41248

Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for …

Fix: after 1.4.0
Fix from $1,600 2022-09-21
Dotci CRITICAL 9.8
CVE-2022-41237

Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote co…

Fix: after 2.40.00
Fix from $2,300 2022-09-21
Dotci CRITICAL 9.8
CVE-2022-41238

A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to th…

Fix: after 2.40.00
Fix from $2,300 2022-09-21
Rqm CRITICAL 9.1
CVE-2022-41241

Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2.8
Fix from $2,300 2022-09-21
Ns Nd Integration Performance Publisher HIGH 8.8
CVE-2022-41227

A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to…

Fix: 4.8.0.130+
Fix from $1,950 2022-09-21
Ns Nd Integration Performance Publisher HIGH 8.8
CVE-2022-41228

A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permiss…

Fix: 4.8.0.130+
Fix from $1,950 2022-09-21
Rundeck HIGH 8.8
CVE-2022-41234

Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users with Overall/Read permissi…

Fix: after 3.6.11
Fix from $1,950 2022-09-21
Security Inspector HIGH 8.8
CVE-2022-41236

A cross-site request forgery (CSRF) vulnerability in Jenkins Security Inspector Plugin 117.v6eecc36919c2 and earlier allows attackers to replace the …

Fix: after 117.v6eecc36919c2
Fix from $1,950 2022-09-21
Smalltest HIGH 8.1
CVE-2022-41243

Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused …

Fix: after 1.0.4
Fix from $1,950 2022-09-21
Build Publisher HIGH 8.0
CVE-2022-41232

A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers to replace any config.xml file …

Fix: after 1.22
Fix from $1,950 2022-09-21
Build Publisher MEDIUM 5.7
CVE-2022-41231

Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenki…

Fix: after 1.22
Fix from $1,600 2022-09-21
Ns Nd Integration Performance Publisher MEDIUM 5.4
CVE-2022-41229

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud T…

Fix: after 4.8.0.134
Fix from $1,600 2022-09-21
Dotci MEDIUM 5.4
CVE-2022-41239

Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a bu…

Fix: after 2.40.00
Fix from $1,600 2022-09-21
Walti MEDIUM 5.4
CVE-2022-41240

Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vu…

Fix: after 1.0.1
Fix from $1,600 2022-09-21
Extreme Feedback MEDIUM 5.4
CVE-2022-41242

A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information a…

Fix: after 1.7
Fix from $1,600 2022-09-21
Wildfly Deployer MEDIUM 5.3
CVE-2022-41235

Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins control…

Fix: after 1.0.2
Fix from $1,600 2022-09-21
Compuware Common Configuration CRITICAL 9.8
CVE-2022-41226

Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: 1.0.15+
Fix from $2,300 2022-09-21
Jenkins MEDIUM 5.4
CVE-2022-41224

Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, …

Fix: 2.370+
Fix from $1,600 2022-09-21
Anchore Container Image Scanner MEDIUM 5.4
CVE-2022-41225

Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored c…

Fix: 1.0.25+
Fix from $1,600 2022-09-21
Git MEDIUM 6.5
CVE-2022-38663

Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username…

Fix: after 4.11.4
Fix from $1,600 2022-08-23
Collabnet MEDIUM 6.5
CVE-2022-38665

Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller …

Fix: after 2.0.8
Fix from $1,600 2022-08-23
Job Configuration History MEDIUM 5.4
CVE-2022-38664

Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, result…

Fix: after 1165.v8cc9fd1f4597
Fix from $1,600 2022-08-23
Coverity HIGH 8.8
CVE-2022-36920

A cross-site request forgery (CSRF) vulnerability in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified …

Fix: after 1.11.4
Fix from $1,950 2022-07-27
Coverity HIGH 8.1
CVE-2022-36921

A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec…

Fix: after 1.11.4
Fix from $1,950 2022-07-27
Lucene Search MEDIUM 6.1
CVE-2022-36922

Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page, resultin…

Fix: after 370.v62a5f618cd3a
Fix from $1,600 2022-07-27
Google Cloud Backup HIGH 8.0
CVE-2022-36916

A cross-site request forgery (CSRF) vulnerability in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers to request a manual backup.

Fix: after 0.6
Fix from $1,950 2022-07-27