Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-24458 A cross-site request forgery (CSRF) vulnerability in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified … Bearychat after 3.0.2 Fix from $1,9502023-01-26 MEDIUM 6.5 CVE-2023-24457 A cross-site request forgery (CSRF) vulnerability in Jenkins Keycloak Authentication Plugin 2.3.0 and earlier allows attackers to trick users into lo… Keycloak Authentication after 2.3.0 Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2023-24459 A missing permission check in Jenkins BearyChat Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec… Bearychat after 3.0.2 Fix from $1,6002023-01-26 CRITICAL 9.8 CVE-2023-24443 Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Testcomplete Support after 2.8.1 Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2023-24444 Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login. Openid after 2.4 Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2023-24456 Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login. Keycloak Authentication after 2.3.0 Fix from $2,3002023-01-26 HIGH 8.8 CVE-2023-24446 A cross-site request forgery (CSRF) vulnerability in Jenkins OpenID Plugin 2.4 and earlier allows attackers to trick users into logging in to the att… Openid after 2.4 Fix from $1,9502023-01-26 HIGH 8.8 CVE-2023-24447 A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers to connect to an attacker-spec… Rabbitmq Consumer after 2.8 Fix from $1,9502023-01-26 HIGH 8.8 CVE-2023-24452 A cross-site request forgery (CSRF) vulnerability in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers to connect to an attacker-sp… Testquality Updater after 1.3 Fix from $1,9502023-01-26 MEDIUM 6.5 CVE-2023-24448 A missing permission check in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers with Overall/Read permission to connect to an attacke… Rabbitmq Consumer after 2.8 Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2023-24450 Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by… View Cloner Mitigation only Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2023-24453 A missing check in Jenkins TestQuality Updater Plugin 1.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifi… Testquality Updater after 1.3 Fix from $1,6002023-01-26 MEDIUM 6.1 CVE-2023-24445 Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins. Openid after 2.4 Fix from $1,6002023-01-26 MEDIUM 5.5 CVE-2023-24454 Jenkins TestQuality Updater Plugin 1.3 and earlier stores the TestQuality Updater password unencrypted in its global configuration file on the Jenkin… Testquality Updater after 1.3 Fix from $1,6002023-01-26 CRITICAL 9.8 CVE-2023-24429 Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitatio… Semantic Versioning 1.15+ Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2023-24430 Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Semantic Versioning 1.15+ Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2023-24441 Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Mstest after 1.0.0 Fix from $2,3002023-01-26 HIGH 8.8 CVE-2023-24432 A cross-site request forgery (CSRF) vulnerability in Jenkins Orka by MacStadium Plugin 1.31 and earlier allows attackers to connect to an attacker-sp… Orka By Macstadium 1.32+ Fix from $1,9502023-01-26 HIGH 8.8 CVE-2023-24434 A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers to connect to an … Github Pull Request Builder after 1.42.2 Fix from $1,9502023-01-26 HIGH 8.8 CVE-2023-24437 A cross-site request forgery (CSRF) vulnerability in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers to connect… Jira Pipeline Steps after 2.0.165.v8846cf59f3db Fix from $1,9502023-01-26 MEDIUM 6.5 CVE-2023-24433 Missing permission checks in Jenkins Orka by MacStadium Plugin 1.31 and earlier allow attackers with Overall/Read permission to connect to an attacke… Orka By Macstadium 1.32+ Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2023-24435 A missing permission check in Jenkins GitHub Pull Request Builder Plugin 1.42.2 and earlier allows attackers with Overall/Read permission to connect … Github Pull Request Builder after 1.42.2 Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2023-24438 A missing permission check in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers with Overall/Read permission to c… Jira Pipeline Steps after 2.0.165.v8846cf59f3db Fix from $1,6002023-01-26 MEDIUM 5.7 CVE-2023-24428 A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in … Bitbucket Oauth 0.13+ Fix from $1,6002023-01-26 MEDIUM 5.5 CVE-2023-24439 Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file on the Jenk… Jira Pipeline Steps after 2.0.165.v8846cf59f3db Fix from $1,6002023-01-26 MEDIUM 5.5 CVE-2023-24440 Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configurat… Jira Pipeline Steps after 2.0.165.v8846cf59f3db Fix from $1,6002023-01-26 MEDIUM 5.5 CVE-2023-24442 Jenkins GitHub Pull Request Coverage Status Plugin 2.2.0 and earlier stores the GitHub Personal Access Token, Sonar access token and Sonar password u… Github Pull Request Coverage Status after 2.2.0 Fix from $1,6002023-01-26 CRITICAL 9.8 CVE-2023-24427 Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login. Bitbucket Oauth after 0.13 Fix from $2,3002023-01-26 HIGH 8.8 CVE-2023-24422 A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with pe… Script Security 1229.v4880b_b_e905a_6+ Fix from $1,9502023-01-26 HIGH 8.8 CVE-2023-24424 Jenkins OpenId Connect Authentication Plugin 2.4 and earlier does not invalidate the previous session on login. Openid Connect Authentication 2.5+ Fix from $1,9502023-01-26