Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filesystem List Parameter MEDIUM 5.4
CVE-2022-34187

Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objects list parameters on views d…

Fix: after 0.0.7
Fix from $1,600 2022-06-23
Hidden Parameter MEDIUM 5.4
CVE-2022-34188

Jenkins Hidden Parameter Plugin 0.0.4 and earlier does not escape the name and description of Hidden Parameter parameters on views displaying paramet…

Fix: after 0.0.4
Fix from $1,600 2022-06-23
Image Tag Parameter MEDIUM 5.4
CVE-2022-34189

Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on views displaying parameters, …

Fix: after 1.10
Fix from $1,600 2022-06-23
Maven Metadata MEDIUM 5.4
CVE-2022-34190

Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.1 and earlier does not escape the name and description of List maven artifact versions p…

Fix: after 2.1
Fix from $1,600 2022-06-23
Ns Nd Integration Performance Publisher MEDIUM 5.4
CVE-2022-34191

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test parameters on views displaying …

Fix: after 4.8.0.77
Fix from $1,600 2022-06-23
Ontrack MEDIUM 5.4
CVE-2022-34192

Jenkins ontrack Jenkins Plugin 4.0.0 and earlier does not escape the name of Ontrack: Multi Parameter choice, Ontrack: Parameter choice, and Ontrack:…

Fix: after 4.0.0
Fix from $1,600 2022-06-23
Package Version MEDIUM 5.4
CVE-2022-34193

Jenkins Package Version Plugin 1.0.1 and earlier does not escape the name of Package version parameters on views displaying parameters, resulting in …

Fix: after 1.0.1
Fix from $1,600 2022-06-23
Readonly Parameter MEDIUM 5.4
CVE-2022-34194

Jenkins Readonly Parameter Plugin 1.0.0 and earlier does not escape the name and description of Readonly String and Readonly Text parameters on views…

Fix: after 1.0.0
Fix from $1,600 2022-06-23
Repository Connector MEDIUM 5.4
CVE-2022-34195

Jenkins Repository Connector Plugin 2.2.0 and earlier does not escape the name and description of Maven Repository Artifact parameters on views displ…

Fix: after 2.2.0
Fix from $1,600 2022-06-23
Rest List Parameter MEDIUM 5.4
CVE-2022-34196

Jenkins REST List Parameter Plugin 1.5.2 and earlier does not escape the name and description of REST list parameters on views displaying parameters,…

Fix: after 1.5.2
Fix from $1,600 2022-06-23
Sauce Ondemand MEDIUM 5.4
CVE-2022-34197

Jenkins Sauce OnDemand Plugin 1.204 and earlier does not escape the name and description of Sauce Labs Browsers parameters on views displaying parame…

Fix: after 1.204
Fix from $1,600 2022-06-23
Xunit CRITICAL 9.1
CVE-2022-34181

Jenkins xUnit Plugin 3.0.8 and earlier implements an agent-to-controller message that creates a user-specified directory if it doesn't exist, and par…

Fix: after 3.0.8
Fix from $2,300 2022-06-23
Jenkins HIGH 7.5
CVE-2022-34174

In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempt…

Fix: after 2.355
Fix from $1,950 2022-06-23
Jenkins HIGH 7.5
CVE-2022-34175

Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fr…

Fix: after 2.355
Fix from $1,950 2022-06-23
Pipeline\ HIGH 7.5
CVE-2022-34177

Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the …

Fix: after 448.v37cea_9a_10a_70
Fix from $1,950 2022-06-23
Embeddable Build Status HIGH 7.5
CVE-2022-34179

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image sty…

Fix: after 2.0.3
Fix from $1,950 2022-06-23
Embeddable Build Status HIGH 7.5
CVE-2022-34180

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides …

Fix: after 2.0.3
Fix from $1,950 2022-06-23
Embeddable Build Status MEDIUM 6.1
CVE-2022-34178

Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting po…

Mitigation only
Fix from $1,600 2022-06-23
Nested View MEDIUM 6.1
CVE-2022-34182

Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) …

Fix: after 1.25
Fix from $1,600 2022-06-23
Jenkins MEDIUM 5.4
CVE-2022-34170

In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name t…

Fix: after 2.355
Fix from $1,600 2022-06-23
Jenkins MEDIUM 5.4
CVE-2022-34171

In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based S…

Fix: after 2.355
Fix from $1,600 2022-06-23
Jenkins MEDIUM 5.4
CVE-2022-34172

In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-s…

Fix: after 2.355
Fix from $1,600 2022-06-23
Jenkins MEDIUM 5.4
CVE-2022-34173

In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, re…

Fix: after 2.355
Fix from $1,600 2022-06-23
Junit MEDIUM 5.4
CVE-2022-34176EPSS 77%

Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS)…

Fix: after 1119.va_a_5e9068da_d7
Fix from $1,600 2022-06-23
Autocomplete Parameter HIGH 8.8
CVE-2022-30969

A cross-site request forgery (CSRF) vulnerability in Jenkins Autocomplete Parameter Plugin 1.1 and earlier allows attackers to execute arbitrary code…

Fix: after 1.1
Fix from $1,950 2022-05-17
Storable Configs HIGH 8.8
CVE-2022-30971

Jenkins Storable Configs Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.0
Fix from $1,950 2022-05-17
Storage Configs HIGH 8.8
CVE-2022-30972

A cross-site request forgery (CSRF) vulnerability in Jenkins Storable Configs Plugin 1.0 and earlier allows attackers to have Jenkins parse a local X…

Fix: after 1.0
Fix from $1,950 2022-05-17
Vboxwrapper MEDIUM 5.4
CVE-2022-30968

Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views displaying parameters, resulting…

Fix: after 1.3
Fix from $1,600 2022-05-17
Autocomplete Parameter MEDIUM 5.4
CVE-2022-30970

Jenkins Autocomplete Parameter Plugin 1.1 and earlier references Dropdown Autocomplete parameter and Auto Complete String parameter names in an unsaf…

Fix: after 1.1
Fix from $1,600 2022-05-17
Ssh HIGH 8.8
CVE-2022-30958

A cross-site request forgery (CSRF) vulnerability in Jenkins SSH Plugin 2.6.1 and earlier allows attackers to connect to an attacker-specified SSH se…

Fix: after 2.6.1
Fix from $1,950 2022-05-17