Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Promoted Builds MEDIUM 5.4
CVE-2022-29045

Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not escape the name and description of Promoted Build parameters o…

Fix: 3.10.1 / 876.v99d29788b_36b_+
Fix from $1,600 2022-04-12
Subversion MEDIUM 5.4
CVE-2022-29046

Jenkins Subversion Plugin 2.15.3 and earlier does not escape the name and description of List Subversion tags (and more) parameters on views displayi…

Fix: 12.5+
Fix from $1,600 2022-04-12
Promoted Builds MEDIUM 5.4
CVE-2022-29049

Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing …

Fix: 3.10.1 / 876.v99d29788b_36b_+
Fix from $1,600 2022-04-12
Pipeline\ MEDIUM 5.3
CVE-2022-29047

Jenkins Pipeline: Shared Groovy Libraries Plugin 564.ve62a_4eb_b_e039 and earlier, except 2.21.3, allows attackers able to submit pull requests (or e…

Fix: 2.21.3 / 566.vd0a_a_3334a_555+
Fix from $1,600 2022-04-12
Coverage\/complexity Scatter Plot HIGH 8.1
CVE-2022-28154

Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.1.1
Fix from $1,950 2022-03-29
Pipeline\ HIGH 8.1
CVE-2022-28155

Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.3
Fix from $1,950 2022-03-29
Pipeline\ MEDIUM 6.5
CVE-2022-28156

Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to copy arbitrary files and directories fro…

Fix: after 1.3
Fix from $1,600 2022-03-29
Pipeline\ MEDIUM 6.5
CVE-2022-28157

Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to upload arbitrary files from the Jenkins …

Fix: after 1.3
Fix from $1,600 2022-03-29
Pipeline\ MEDIUM 6.5
CVE-2022-28158

A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Overall/Read permission to enumerate cr…

Fix: after 1.3
Fix from $1,600 2022-03-29
Tests Selector MEDIUM 6.5
CVE-2022-28160

Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on the Jenkins controller.

Fix: after 1.3.3
Fix from $1,600 2022-03-29
Tests Selector MEDIUM 5.4
CVE-2022-28159

Jenkins Tests Selector Plugin 1.3.3 and earlier does not escape the Properties File Path option for Choosing Tests parameters, resulting in a stored …

Fix: after 1.3.3
Fix from $1,600 2022-03-29
Job And Node Ownership HIGH 8.8
CVE-2022-28150

A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to change the owners a…

Fix: after 0.13.0
Fix from $1,950 2022-03-29
Job And Node Ownership MEDIUM 5.4
CVE-2022-28149

Jenkins Job and Node ownership Plugin 0.13.0 and earlier does not escape the names of the secondary owners, resulting in a stored cross-site scriptin…

Fix: after 0.13.0
Fix from $1,600 2022-03-29
Sitemonitor MEDIUM 5.4
CVE-2022-28153

Jenkins SiteMonitor Plugin 0.6 and earlier does not escape URLs of sites to monitor in tooltips, resulting in a stored cross-site scripting (XSS) vul…

Fix: after 0.6
Fix from $1,600 2022-03-29
Jiratestresultreporter HIGH 8.8
CVE-2022-28136

A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect …

Fix: after 165.v817928553942
Fix from $1,950 2022-03-29
Flaky Test Handler HIGH 8.1
CVE-2022-28140

Jenkins Flaky Test Handler Plugin 1.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.2.1
Fix from $1,950 2022-03-29
Proxmox HIGH 7.5
CVE-2022-28142

Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM when configured to ignore SS…

Fix: after 0.6.0
Fix from $1,950 2022-03-29
Instant Messaging MEDIUM 6.5
CVE-2022-28135

Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on J…

Fix: 1.42+
Fix from $1,600 2022-03-29
Proxmox MEDIUM 6.5
CVE-2022-28141

Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml file on the Jenkins controller w…

Fix: after 0.5.0
Fix from $1,600 2022-03-29
Proxmox MEDIUM 6.5
CVE-2022-28143

A cross-site request forgery (CSRF) vulnerability in Jenkins Proxmox Plugin 0.7.0 and earlier allows attackers to connect to an attacker-specified ho…

Fix: after 0.7.0
Fix from $1,600 2022-03-29
Proxmox MEDIUM 6.5
CVE-2022-28144

Jenkins Proxmox Plugin 0.7.0 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permissi…

Fix: after 0.7.0
Fix from $1,600 2022-03-29
Continuous Integration With Toad Edge MEDIUM 6.5
CVE-2022-28146

Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Item/Configure permission to read arbitrary files on the J…

Fix: after 2.3
Fix from $1,600 2022-03-29
Continuous Integration With Toad Edge MEDIUM 6.5
CVE-2022-28148

The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to files as absolute on Windows, re…

Fix: after 2.3
Fix from $1,600 2022-03-29
Bitbucket Server Integration MEDIUM 5.4
CVE-2022-28133

Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored …

Fix: after 3.1.0
Fix from $1,600 2022-03-29
Bitbucket Server Integration MEDIUM 5.4
CVE-2022-28134

Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with O…

Fix: after 3.1.0
Fix from $1,600 2022-03-29
Continuous Integration With Toad Edge MEDIUM 5.4
CVE-2022-28145

Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier does not apply Content-Security-Policy headers to report files it serves, result…

Fix: after 2.3
Fix from $1,600 2022-03-29
Dbcharts MEDIUM 6.5
CVE-2022-27216

Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file on the Jenkins controller whe…

Fix: after 0.5.2
Fix from $1,600 2022-03-15
Vmware Vrealize Codestream MEDIUM 6.5
CVE-2022-27217

Jenkins Vmware vRealize CodeStream Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they c…

Fix: after 1.2
Fix from $1,600 2022-03-15
List Git Branches Parameter MEDIUM 5.4
CVE-2022-27212

Jenkins List Git Branches Parameter Plugin 0.0.9 and earlier does not escape the name of the 'List Git branches (and more)' parameter, resulting in a…

Fix: after 0.0.9
Fix from $1,600 2022-03-15
Environment Dashboard MEDIUM 5.4
CVE-2022-27213

Jenkins Environment Dashboard Plugin 1.1.10 and earlier does not escape the Environment order and the Component order configuration values in its vie…

Fix: after 1.1.10
Fix from $1,600 2022-03-15