Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openshift Deployer MEDIUM 6.5
CVE-2022-36906

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to connect to an attacker-s…

Fix: after 1.2.0
Fix from $1,600 2022-07-27
Openshift Deployer MEDIUM 6.5
CVE-2022-36907

A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to connect to an atta…

Fix: after 1.2.0
Fix from $1,600 2022-07-27
Openshift Deployer MEDIUM 6.5
CVE-2022-36908

A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence …

Fix: after 1.2.0
Fix from $1,600 2022-07-27
Openshift Deployer MEDIUM 6.5
CVE-2022-36909

A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to check for the exis…

Fix: after 1.2.0
Fix from $1,600 2022-07-27
Openstack Heat MEDIUM 6.5
CVE-2022-36911

A cross-site request forgery (CSRF) vulnerability in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers to connect to an attacker-specifi…

Fix: after 1.5
Fix from $1,600 2022-07-27
Maven Metadata MEDIUM 5.4
CVE-2022-36905

Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven …

Fix: after 2.2
Fix from $1,600 2022-07-27
Lucene Search MEDIUM 5.4
CVE-2022-36910

Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Ove…

Fix: after 370.v62a5f618cd3a
Fix from $1,600 2022-07-27
Deployer Framework HIGH 8.8
CVE-2022-36889

Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployme…

Fix: after 85.v1d1888e8c021
Fix from $1,950 2022-07-27
Compuware Ispw Operations HIGH 8.2
CVE-2022-36899

Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers ab…

Fix: 1.0.9+
Fix from $1,950 2022-07-27
Compuware Zadviser Api HIGH 8.2
CVE-2022-36900

Jenkins Compuware zAdviser API Plugin 1.0.3 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able …

Fix: after 1.0.3
Fix from $1,950 2022-07-27
Hashicorp Vault MEDIUM 6.5
CVE-2022-36888

A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain …

Fix: after 354.vdb_858fd6b_f48
Fix from $1,600 2022-07-27
Clif Performance Testing MEDIUM 6.5
CVE-2022-36894

An arbitrary file write vulnerability in Jenkins CLIF Performance Testing Plugin 64.vc0d66de1dfb_f and earlier allows attackers with Overall/Read per…

Fix: after 64.vc0d66de1dfb_f
Fix from $1,600 2022-07-27
Compuware Source Code Download For Endevor\, Pds\, And Ispw MEDIUM 6.5
CVE-2022-36896

A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier allows attackers with Overa…

Fix: after 2.0.12
Fix from $1,600 2022-07-27
Http Request MEDIUM 6.5
CVE-2022-36901

Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller whe…

Fix: after 1.15
Fix from $1,600 2022-07-27
Dynamic Extended Choice Parameter MEDIUM 5.4
CVE-2022-36902

Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape several fields of Moded Extended Choice parameters, resulting in a…

Fix: after 1.0.1
Fix from $1,600 2022-07-27
Git HIGH 8.8
CVE-2022-36882

A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to u…

Fix: after 4.11.3
Fix from $1,950 2022-07-27
Git Client HIGH 8.1
CVE-2022-36881

Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-…

Fix: after 3.11.0
Fix from $1,950 2022-07-27
Git HIGH 7.5
CVE-2022-36883EPSS 6%

A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an a…

Fix: after 4.11.3
Fix from $1,950 2022-07-27
Git MEDIUM 5.3
CVE-2022-36884

The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to…

Fix: after 4.11.3
Fix from $1,600 2022-07-27
GitHub MEDIUM 5.3
CVE-2022-36885

Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatu…

Fix: after 1.34.4
Fix from $1,600 2022-07-27
Google Login MEDIUM 6.5
CVE-2015-5298

The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are suppo…

Mitigation only
Fix from $1,600 2022-07-07
Rqm MEDIUM 6.5
CVE-2022-34810

A missing check in Jenkins RQM Plugin 2.8 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials store…

Fix: after 2.8
Fix from $1,600 2022-06-30
Hpe Network Virtualization MEDIUM 6.5
CVE-2022-34816

Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can …

Mitigation only
Fix from $1,600 2022-06-30
Skype Notifier MEDIUM 6.5
CVE-2022-34805

Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can…

Fix: after 1.1.0
Fix from $1,600 2022-06-30
Jigomerge MEDIUM 6.5
CVE-2022-34806

Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by u…

Fix: after 0.9
Fix from $1,600 2022-06-30
Elasticsearch Query MEDIUM 6.5
CVE-2022-34807

Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it …

Fix: after 1.2
Fix from $1,600 2022-06-30
Rqm MEDIUM 6.5
CVE-2022-34809

Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by…

Fix: after 2.8
Fix from $1,600 2022-06-30
Recipe HIGH 8.8
CVE-2022-34793

Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.2
Fix from $1,950 2022-06-30
Recipe HIGH 8.0
CVE-2022-34792

A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an HTTP request to an attacker-sp…

Fix: after 1.2
Fix from $1,950 2022-06-30
Recipe MEDIUM 6.5
CVE-2022-34794

Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacke…

Fix: after 1.2
Fix from $1,600 2022-06-30