Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Agent Server Parameter MEDIUM 5.4
CVE-2022-25191

Jenkins Agent Server Parameter Plugin 1.0 and earlier does not escape parameter names of agent server parameters, resulting in a stored cross-site sc…

Fix: after 1.0
Fix from $1,600 2022-02-15
Gitlab Authentication MEDIUM 5.4
CVE-2022-25196

Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication pro…

Fix: after 1.13
Fix from $1,600 2022-02-15
Team Views MEDIUM 5.4
CVE-2022-25203

Jenkins Team Views Plugin 0.9.0 and earlier does not escape team names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by…

Fix: after 0.9.0
Fix from $1,600 2022-02-15
Pipeline\ HIGH 8.8
CVE-2022-25181

A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure…

Fix: after 552.vd9cc05b8a2e1
Fix from $1,950 2022-02-15
Pipeline\ HIGH 8.8
CVE-2022-25182

A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure…

Fix: after 552.vd9cc05b8a2e1
Fix from $1,950 2022-02-15
Pipeline\ HIGH 8.8
CVE-2022-25183

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories witho…

Fix: after 552.vd9cc05b8a2e1
Fix from $1,950 2022-02-15
Pipeline\ MEDIUM 6.5
CVE-2022-25184

Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipeline script using the Pipeline S…

Fix: after 2.15
Fix from $1,600 2022-02-15
Hashicorp Vault MEDIUM 6.5
CVE-2022-25186

Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the ag…

Fix: after 3.8.0
Fix from $1,600 2022-02-15
Support Core MEDIUM 6.5
CVE-2022-25187

Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.

Fix: after 2.79
Fix from $1,600 2022-02-15
Generic Webhook Trigger MEDIUM 5.4
CVE-2022-25185

Jenkins Generic Webhook Trigger Plugin 1.81 and earlier does not escape the build cause when using the webhook, resulting in a stored cross-site scri…

Fix: after 1.81
Fix from $1,600 2022-02-15
Custom Checkbox Parameter MEDIUM 5.4
CVE-2022-25189

Jenkins Custom Checkbox Parameter Plugin 1.1 and earlier does not escape parameter names of custom checkbox parameters, resulting in a stored cross-s…

Fix: after 1.1
Fix from $1,600 2022-02-15
Pipeline\ HIGH 8.8
CVE-2022-25173

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typ…

Fix: after 2648.va9433432b33c
Fix from $1,950 2022-02-15
Pipeline\ HIGH 8.8
CVE-2022-25174

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libr…

Fix: after 552.vd9cc05b8a2e1
Fix from $1,950 2022-02-15
Pipeline\ HIGH 8.8
CVE-2022-25175

Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, all…

Fix: after 706.vd43c65dec013
Fix from $1,950 2022-02-15
Pipeline\ MEDIUM 6.5
CVE-2022-25176

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checkout directory for the configur…

Fix: after 2648.va9433432b33c
Fix from $1,600 2022-02-15
Pipeline\ MEDIUM 6.5
CVE-2022-25177

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic links to locations outside of the expected Pipeline l…

Fix: after 552.vd9cc05b8a2e1
Fix from $1,600 2022-02-15
Pipeline\ MEDIUM 6.5
CVE-2022-25178

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier does not restrict the names of resources passed to the libraryResource…

Fix: after 552.vd9cc05b8a2e1
Fix from $1,600 2022-02-15
Pipeline\ MEDIUM 6.5
CVE-2022-25179

Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the checkout directory for the conf…

Fix: after 706.vd43c65dec013
Fix from $1,600 2022-02-15
Jenkins HIGH 7.5
CVE-2022-0538

Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vuln…

Fix: 2.319.3 / 2.334+
Fix from $1,950 2022-02-09
Jenkins HIGH 7.5
CVE-2021-43859EPSS 8%

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 1…

Fix: 1.4.19 / 2.319.3+
Fix from $1,950 2022-02-01
Debian Package Builder HIGH 8.8
CVE-2022-23118

Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-spec…

Fix: after 1.6.11
Fix from $1,950 2022-01-12
Warnings Next Generation HIGH 8.1
CVE-2022-23107

Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with I…

Fix: 9.0.2 / 9.5.2+
Fix from $1,950 2022-01-12
Conjur Secrets HIGH 7.5
CVE-2022-23116

Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets sto…

Fix: after 1.0.9
Fix from $1,950 2022-01-12
Conjur Secrets HIGH 7.5
CVE-2022-23117

Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all userna…

Fix: after 1.0.9
Fix from $1,950 2022-01-12
Bitbucket Branch Source HIGH 7.1
CVE-2022-20619

A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect…

Fix: after 2.9.10
Fix from $1,950 2022-01-12
Active Directory MEDIUM 6.5
CVE-2022-23105

Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory server…

Fix: after 2.25
Fix from $1,600 2022-01-12
Hashicorp Vault MEDIUM 6.5
CVE-2022-23109

Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipelin…

Fix: after 3.7.0
Fix from $1,600 2022-01-12
Publish Over Ssh MEDIUM 6.5
CVE-2022-23112

A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access to connect to an attacker-sp…

Fix: after 1.22
Fix from $1,600 2022-01-12
Metrics MEDIUM 5.5
CVE-2022-20621

Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can b…

Fix: after 4.0.2.8
Fix from $1,600 2022-01-12
Badge MEDIUM 5.4
CVE-2022-23108

Jenkins Badge Plugin 1.9 and earlier does not escape the description and does not check for allowed protocols when creating a badge, resulting in a s…

Fix: after 1.9
Fix from $1,600 2022-01-12