Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Extended Choice Parameter HIGH 8.8
CVE-2022-27204

A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers to connect to …

Fix: after 346.vd87693c5a_86c
Fix from $1,950 2022-03-15
Gitlab Authentication MEDIUM 6.5
CVE-2022-27206

Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins contro…

Fix: after 1.13
Fix from $1,600 2022-03-15
Kubernetes Continuous Deploy MEDIUM 6.5
CVE-2022-27208

Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read arbitrary files on the Jenkins …

Fix: after 2.3.1
Fix from $1,600 2022-03-15
Kubernetes Continuous Deploy MEDIUM 6.5
CVE-2022-27209

A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerat…

Fix: after 2.3.1
Fix from $1,600 2022-03-15
Kubernetes Continuous Deploy MEDIUM 6.5
CVE-2022-27210

A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an …

Fix: after 2.3.1
Fix from $1,600 2022-03-15
Kubernetes Continuous Deploy MEDIUM 6.5
CVE-2022-27211

A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect …

Fix: after 2.3.1
Fix from $1,600 2022-03-15
Cloudbees Aws Credentials HIGH 8.0
CVE-2022-27198

A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Ove…

Fix: 1.28.2+
Fix from $1,950 2022-03-15
Semantic Versioning MEDIUM 6.5
CVE-2022-27201

Jenkins Semantic Versioning Plugin 1.13 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitatio…

Fix: after 1.13
Fix from $1,600 2022-03-15
Extended Choice Parameter MEDIUM 6.5
CVE-2022-27203

Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Item/Configure permission to read values from arbitrary…

Fix: after 346.vd87693c5a_86c
Fix from $1,600 2022-03-15
Dashboard View MEDIUM 5.4
CVE-2022-27197

Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source URL, resulting in a stored cros…

Fix: 2.18.1+
Fix from $1,600 2022-03-15
Extended Choice Parameter MEDIUM 5.4
CVE-2022-27202

Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value and description of extended choice parameters of ra…

Fix: after 346.vd87693c5a_86c
Fix from $1,600 2022-03-15
Parameterized Trigger MEDIUM 5.5
CVE-2022-27195

Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger P…

Fix: 2.43.1+
Fix from $1,600 2022-03-15
Favorite MEDIUM 5.4
CVE-2022-27196

Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a stored cross-site scripting (XSS) …

Fix: 2.4.1+
Fix from $1,600 2022-03-15
Dbcharts HIGH 8.8
CVE-2022-25205

A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified d…

Fix: after 0.5.2
Fix from $1,950 2022-02-15
Dbcharts HIGH 8.8
CVE-2022-25206

A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified databa…

Fix: after 0.5.2
Fix from $1,950 2022-02-15
Chef Sinatra HIGH 8.8
CVE-2022-25207

A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP reque…

Fix: after 1.20
Fix from $1,950 2022-02-15
Chef Sinatra HIGH 8.8
CVE-2022-25208

A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP…

Fix: after 1.20
Fix from $1,950 2022-02-15
Chef Sinatra HIGH 8.8
CVE-2022-25209

Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.20
Fix from $1,950 2022-02-15
Swamp HIGH 8.8
CVE-2022-25211

A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifie…

Fix: after 1.2.6
Fix from $1,950 2022-02-15
Swamp HIGH 8.8
CVE-2022-25212

A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect to an attacker-specified web …

Fix: after 1.2.6
Fix from $1,950 2022-02-15
Convertigo Mobile Platform MEDIUM 6.5
CVE-2022-25210

Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier uses static fields to store job configuration information, allowing attackers with Item/Con…

Fix: after 1.1
Fix from $1,600 2022-02-15
Doktor MEDIUM 5.4
CVE-2022-25204

Jenkins Doktor Plugin 0.4.1 and earlier implements functionality that allows agent processes to render files on the controller as Markdown or Asciido…

Fix: after 0.4.1
Fix from $1,600 2022-02-15
Snow Commander HIGH 8.8
CVE-2022-25192

A cross-site request forgery (CSRF) vulnerability in Jenkins Snow Commander Plugin 1.10 and earlier allows attackers to connect to an attacker-specif…

Fix: after 1.10
Fix from $1,950 2022-02-15
Autonomiq HIGH 8.8
CVE-2022-25194

A cross-site request forgery (CSRF) vulnerability in Jenkins autonomiq Plugin 1.15 and earlier allows attackers to connect to an attacker-specified U…

Fix: after 1.15
Fix from $1,950 2022-02-15
Scp Publisher HIGH 8.8
CVE-2022-25198

A cross-site request forgery (CSRF) vulnerability in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers to connect to an attacker-specifie…

Fix: after 1.8
Fix from $1,950 2022-02-15
Scp Publisher HIGH 8.8
CVE-2022-25199

A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-sp…

Fix: after 1.8
Fix from $1,950 2022-02-15
Checkmarx HIGH 8.8
CVE-2022-25200

A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specifi…

Fix: after 2022.1.2
Fix from $1,950 2022-02-15
Snow Commander MEDIUM 6.5
CVE-2022-25193

Missing permission checks in Jenkins Snow Commander Plugin 1.10 and earlier allow attackers with Overall/Read permission to connect to an attacker-sp…

Fix: after 1.10
Fix from $1,600 2022-02-15
Hashicorp Vault MEDIUM 6.5
CVE-2022-25197

Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenk…

Fix: after 336.v182c0fbaaeb7
Fix from $1,600 2022-02-15
Checkmarx MEDIUM 6.5
CVE-2022-25201

Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-spe…

Fix: after 2022.1.2
Fix from $1,600 2022-02-15