Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Validating Email Parameter MEDIUM 5.4
CVE-2022-34791

Jenkins Validating Email Parameter Plugin 1.10 and earlier does not escape the name and description of its parameter type, resulting in a stored cros…

Fix: after 1.10
Fix from $1,600 2022-06-30
Deployment Dashboard MEDIUM 5.4
CVE-2022-34795

Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard view, resulting in a stored cros…

Fix: after 1.0.10
Fix from $1,600 2022-06-30
Matrix Reloaded MEDIUM 6.5
CVE-2022-34789

A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix bui…

Fix: after 1.1.3
Fix from $1,600 2022-06-30
Rich Text Publisher MEDIUM 5.4
CVE-2022-34786

Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resulting in a stored cross-site scri…

Fix: after 1.4
Fix from $1,600 2022-06-30
Project Inheritance MEDIUM 5.4
CVE-2022-34787

Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scriptin…

Fix: after 21.04.03
Fix from $1,600 2022-06-30
Matrix Reloaded MEDIUM 5.4
CVE-2022-34788

Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnera…

Fix: after 1.1.3
Fix from $1,600 2022-06-30
Extreme Feedback Panel MEDIUM 5.4
CVE-2022-34790

Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a stored cross-site scripting (X…

Fix: after 2.0.1
Fix from $1,600 2022-06-30
Xebialabs Xl Release MEDIUM 6.5
CVE-2022-34780

A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacke…

Fix: after 22.0.0
Fix from $1,600 2022-06-30
Xebialabs Xl Release MEDIUM 6.5
CVE-2022-34781

Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an att…

Fix: after 22.0.0
Fix from $1,600 2022-06-30
Plot MEDIUM 5.4
CVE-2022-34783EPSS 81%

Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable …

Fix: after 2.1.10
Fix from $1,600 2022-06-30
Build Metrics MEDIUM 5.4
CVE-2022-34784

Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-site scripting (XSS) vulnerab…

Mitigation only
Fix from $1,600 2022-06-30
GitLab MEDIUM 5.4
CVE-2022-34777EPSS 72%

Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-triggered builds, resulting in a st…

Fix: after 1.5.34
Fix from $1,600 2022-06-30
Testng Results MEDIUM 5.4
CVE-2022-34778

Jenkins TestNG Results Plugin 554.va4a552116332 and earlier renders the unescaped test descriptions and exception messages provided in test results i…

Fix: after 554.va4a552116332
Fix from $1,600 2022-06-30
Squash Tm Publisher MEDIUM 6.5
CVE-2022-34213

Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file on the Jenkins co…

Fix: after 1.0.0
Fix from $1,600 2022-06-23
Vrealize Orchestrator MEDIUM 5.7
CVE-2022-34212

A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST…

Fix: after 3.0
Fix from $1,600 2022-06-23
Convertigo Mobile Platform HIGH 8.8
CVE-2022-34200

A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers to connect to an atta…

Fix: after 1.1
Fix from $1,950 2022-06-23
Easyqa HIGH 8.8
CVE-2022-34203

A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect to an attacker-specified HTTP …

Fix: after 1.0
Fix from $1,950 2022-06-23
Convertigo Mobile Platform MEDIUM 6.5
CVE-2022-34199

Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they c…

Fix: after 1.1
Fix from $1,600 2022-06-23
Convertigo Mobile Platform MEDIUM 6.5
CVE-2022-34201

A missing permission check in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to a…

Fix: after 1.1
Fix from $1,600 2022-06-23
Easyqa MEDIUM 6.5
CVE-2022-34202

Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be …

Fix: after 1.0
Fix from $1,600 2022-06-23
Jianliao Notification MEDIUM 6.5
CVE-2022-34205

A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests…

Fix: after 1.1
Fix from $1,600 2022-06-23
Beaker Builder MEDIUM 6.5
CVE-2022-34207

A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specif…

Fix: after 1.10
Fix from $1,600 2022-06-23
Threadfix MEDIUM 6.5
CVE-2022-34209

A cross-site request forgery (CSRF) vulnerability in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers to connect to an attacker-specified …

Fix: after 1.5.4
Fix from $1,600 2022-06-23
Threadfix MEDIUM 6.5
CVE-2022-34210

A missing permission check in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec…

Fix: after 1.5.4
Fix from $1,600 2022-06-23
Vrealize Orchestrator MEDIUM 6.5
CVE-2022-34211

A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers to send an HTTP POST reque…

Fix: after 3.0
Fix from $1,600 2022-06-23
Stash Branch Parameter MEDIUM 5.4
CVE-2022-34198

Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier does not escape the name and description of Stash Branch parameters on views displaying param…

Fix: after 0.3.0
Fix from $1,600 2022-06-23
Agent Server Parameter MEDIUM 5.4
CVE-2022-34183

Jenkins Agent Server Parameter Plugin 1.1 and earlier does not escape the name and description of Agent Server parameters on views displaying paramet…

Fix: after 1.1
Fix from $1,600 2022-06-23
Crx Content Package Deployer MEDIUM 5.4
CVE-2022-34184

Jenkins CRX Content Package Deployer Plugin 1.9 and earlier does not escape the name and description of CRX Content Package Choice parameters on view…

Fix: after 1.9
Fix from $1,600 2022-06-23
Date Parameter MEDIUM 5.4
CVE-2022-34185

Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting…

Fix: after 0.0.4
Fix from $1,600 2022-06-23
Dynamic Extended Choice Parameter MEDIUM 5.4
CVE-2022-34186

Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape the name and description of Moded Extended Choice parameters on vi…

Fix: after 1.0.1
Fix from $1,600 2022-06-23