Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ssh MEDIUM 6.5
CVE-2022-30959

A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified …

Fix: after 2.6.1
Fix from $1,600 2022-05-17
Application Detector MEDIUM 5.4
CVE-2022-30960

Jenkins Application Detector Plugin 1.0.8 and earlier does not escape the name of Chois Application Version parameters on views displaying parameters…

Fix: after 1.0.8
Fix from $1,600 2022-05-17
Autocomplete Parameter MEDIUM 5.4
CVE-2022-30961

Jenkins Autocomplete Parameter Plugin 1.1 and earlier does not escape the name of Dropdown Autocomplete and Auto Complete String parameters on views …

Fix: after 1.1
Fix from $1,600 2022-05-17
Global Variable String Parameter MEDIUM 5.4
CVE-2022-30962

Jenkins Global Variable String Parameter Plugin 1.2 and earlier does not escape the name and description of Global Variable String parameters on view…

Fix: after 1.2
Fix from $1,600 2022-05-17
Jdk Parameter MEDIUM 5.4
CVE-2022-30963

Jenkins JDK Parameter Plugin 1.0 and earlier does not escape the name and description of JDK parameters on views displaying parameters, resulting in …

Fix: after 1.0
Fix from $1,600 2022-05-17
Multiselect Parameter MEDIUM 5.4
CVE-2022-30964

Jenkins Multiselect parameter Plugin 1.3 and earlier does not escape the name and description of Multiselect parameters on views displaying parameter…

Fix: after 1.3
Fix from $1,600 2022-05-17
Promoted Builds MEDIUM 5.4
CVE-2022-30965

Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level parameters on views displaying pa…

Fix: after 1.9
Fix from $1,600 2022-05-17
Random String Parameter MEDIUM 5.4
CVE-2022-30966

Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String parameters on views displaying param…

Fix: after 1.0
Fix from $1,600 2022-05-17
Selection Tasks MEDIUM 5.4
CVE-2022-30967

Jenkins Selection tasks Plugin 1.0 and earlier does not escape the name and description of Script Selection task variable parameters on views display…

Fix: after 1.0
Fix from $1,600 2022-05-17
Wmi Windows Agents HIGH 8.8
CVE-2022-30950

Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library which has a buffer overflow vulnerability that may allo…

Fix: 1.8.1+
Fix from $1,950 2022-05-17
Wmi Windows Agents HIGH 8.8
CVE-2022-30951

Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing…

Fix: 1.8.1+
Fix from $1,950 2022-05-17
Blue Ocean MEDIUM 6.5
CVE-2022-30952

Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-…

Fix: after 1.25.3
Fix from $1,600 2022-05-17
Blue Ocean MEDIUM 6.5
CVE-2022-30953

A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to connect to an attacker-specifie…

Fix: after 1.25.3
Fix from $1,600 2022-05-17
Blue Ocean MEDIUM 6.5
CVE-2022-30954

Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read perm…

Fix: after 1.25.3
Fix from $1,600 2022-05-17
GitLab MEDIUM 6.5
CVE-2022-30955

Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to …

Fix: after 1.5.31
Fix from $1,600 2022-05-17
Rundeck MEDIUM 5.4
CVE-2022-30956EPSS 73%

Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (X…

Fix: after 3.6.10
Fix from $1,600 2022-05-17
Pipeline\ HIGH 8.5
CVE-2022-30945

Jenkins Pipeline: Groovy Plugin 2689.v434009a_31b_f1 and earlier allows loading any Groovy source files on the classpath of Jenkins and Jenkins plugi…

Fix: 2689.v434009a_31b_f1+
Fix from $1,950 2022-05-17
Git HIGH 7.5
CVE-2022-30947

Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controlle…

Fix: 4.11.2+
Fix from $1,950 2022-05-17
Mercurial HIGH 7.5
CVE-2022-30948

Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins contr…

Fix: 2.16.1+
Fix from $1,950 2022-05-17
Repo MEDIUM 5.3
CVE-2022-30949

Jenkins REPO Plugin 1.14.0 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controll…

Fix: 1.15.0+
Fix from $1,600 2022-05-17
Publish Over Ftp HIGH 8.8
CVE-2022-29050

A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over FTP Plugin 1.16 and earlier allows attackers to connect to an FTP server us…

Fix: after 1.16
Fix from $1,950 2022-04-12
Credentials MEDIUM 5.4
CVE-2022-29036EPSS 79%

Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2, and 2.6.1.1, does not escape…

Fix: 2.6.1.1 / 1074.1076.v39c30cecb_0e2+
Fix from $1,600 2022-04-12
Cvs MEDIUM 5.4
CVE-2022-29037

Jenkins CVS Plugin 2.19 and earlier does not escape the name and description of CVS Symbolic Name parameters on views displaying parameters, resultin…

Fix: after 2.19
Fix from $1,600 2022-04-12
Extended Choice Parameter MEDIUM 5.4
CVE-2022-29038

Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the name and description of Extended Choice parameters on vie…

Fix: after 346.vd87693c5a_86c
Fix from $1,600 2022-04-12
Gerrit Trigger MEDIUM 5.4
CVE-2022-29039

Jenkins Gerrit Trigger Plugin 2.35.2 and earlier does not escape the name and description of Base64 Encoded String parameters on views displaying par…

Fix: after 2.35.2
Fix from $1,600 2022-04-12
Git Parameter MEDIUM 5.4
CVE-2022-29040

Jenkins Git Parameter Plugin 0.9.15 and earlier does not escape the name and description of Git parameters on views displaying parameters, resulting …

Fix: after 0.9.15
Fix from $1,600 2022-04-12
Jira MEDIUM 5.4
CVE-2022-29041

Jenkins Jira Plugin 3.7 and earlier, except 3.6.1, does not escape the name and description of Jira Issue and Jira Release Version parameters on view…

Fix: 3.6.1+
Fix from $1,600 2022-04-12
Job Generator MEDIUM 5.4
CVE-2022-29042

Jenkins Job Generator Plugin 1.22 and earlier does not escape the name and description of Generator Parameter and Generator Choice parameters on Job …

Fix: after 1.22
Fix from $1,600 2022-04-12
Mask Passwords MEDIUM 5.4
CVE-2022-29043

Jenkins Mask Passwords Plugin 3.0 and earlier does not escape the name and description of Non-Stored Password parameters on views displaying paramete…

Fix: after 3.0
Fix from $1,600 2022-04-12
Node And Label Parameter MEDIUM 5.4
CVE-2022-29044

Jenkins Node and Label parameter Plugin 1.10.3 and earlier does not escape the name and description of Node and Label parameters on views displaying …

Fix: after 1.10.3
Fix from $1,600 2022-04-12