Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-24426 Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login. Azure Ad after 303.va_91ef20ee49f Fix from $1,9502023-01-26 MEDIUM 6.5 CVE-2023-24423 A cross-site request forgery (CSRF) vulnerability in Jenkins Gerrit Trigger Plugin 2.38.0 and earlier allows attackers to rebuild previous builds tri… Gerrit Trigger 2.38.1+ Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2023-24425 Jenkins Kubernetes Credentials Provider Plugin 1.208.v128ee9800c04 and earlier does not set the appropriate context for Kubernetes credentials lookup… Kubernetes Credentials Provider after 1.208.v128ee9800c04 Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2022-46688 A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins conne… Sonar Gerrit after 377.v8f3808963dc5 Fix from $1,6002022-12-12 MEDIUM 5.4 CVE-2022-46684 Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTML reports,… Checkmarx 2022.4.3+ Fix from $1,6002022-12-12 MEDIUM 5.4 CVE-2022-46686 Jenkins Custom Build Properties Plugin 2.79.vc095ccc85094 and earlier does not escape property values and build display names on the Custom Build Pro… Custom Build Properties after 2.79.vc095ccc85094 Fix from $1,6002022-12-12 MEDIUM 5.4 CVE-2022-46687 Jenkins Spring Config Plugin 2.0.0 and earlier does not escape build display names shown on the Spring Config view, resulting in a stored cross-site … Spring Config 2.0.1+ Fix from $1,6002022-12-12 CRITICAL 9.8 CVE-2022-46682 Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Plot 2.1.12+ Fix from $2,3002022-12-12 MEDIUM 6.1 CVE-2022-46683 Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkin… Google Login 1.7+ Fix from $1,6002022-12-12 MEDIUM 5.4 CVE-2022-45401 Jenkins Associated Files Plugin 0.2.1 and earlier does not escape names of associated files, resulting in a stored cross-site scripting (XSS) vulnera… Associated Files after 0.2.1 Fix from $1,6002022-11-15 CRITICAL 9.8 CVE-2022-45397 Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Osf Builder Suite \ after 1.0.2 Fix from $2,3002022-11-15 CRITICAL 9.8 CVE-2022-45400 Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Japex after 1.7 Fix from $2,3002022-11-15 CRITICAL 9.8 CVE-2022-45395 Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Cccc after 0.6 Fix from $2,3002022-11-15 CRITICAL 9.8 CVE-2022-45396 Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Sourcemonitor after 0.2 Fix from $2,3002022-11-15 HIGH 7.5 CVE-2022-45388 Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers… Config Rotator after 2.0.1 Fix from $1,9502022-11-15 HIGH 7.5 CVE-2022-45391 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname v… Ns Nd Integration Performance Publisher 4.8.0.146+ Fix from $1,9502022-11-15 MEDIUM 6.5 CVE-2022-45392 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins cont… Ns Nd Integration Performance Publisher 4.8.0.146+ Fix from $1,6002022-11-15 MEDIUM 5.4 CVE-2022-45387 Jenkins BART Plugin 1.0.3 and earlier does not escape the parsed content of build logs before rendering it on the Jenkins UI, resulting in a stored c… Bart after 1.0.3 Fix from $1,6002022-11-15 MEDIUM 5.3 CVE-2022-45389 A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an at… Xp Dev after 1.0 Fix from $1,6002022-11-15 HIGH 8.1 CVE-2022-45381 Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of Apache Com… Pipeline Utility Steps 2.13.2+ Fix from $1,9502022-11-15 HIGH 7.5 CVE-2022-38666 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for… Ns Nd Integration Performance Publisher after 4.8.0.146 Fix from $1,9502022-11-15 HIGH 7.5 CVE-2022-45379 Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the script, making it vulnerable … Script Security 1190.v65867a_a_47126+ Fix from $1,9502022-11-15 HIGH 7.5 CVE-2022-45385 A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger… Cloudbees Docker Hub\/registry Notification 2.6.2.1+ Fix from $1,9502022-11-15 MEDIUM 6.5 CVE-2022-45383 An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission… Support Core 1206.1208.v9b_7a_1d48db_0f+ Fix from $1,6002022-11-15 MEDIUM 6.5 CVE-2022-45384 Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins control… Reverse Proxy Auth 1.7.4+ Fix from $1,6002022-11-15 MEDIUM 5.5 CVE-2022-45386 Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Violations after 0.7.11 Fix from $1,6002022-11-15 MEDIUM 5.4 CVE-2022-45380 Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in… Junit 1160.vf1f01a_a_ea_b_7f+ Fix from $1,6002022-11-15 MEDIUM 5.4 CVE-2022-45382 Jenkins Naginator Plugin 1.18.1 and earlier does not escape display names of source builds in builds that were triggered via Retry action, resulting … Naginator 1.18.2+ Fix from $1,6002022-11-15 MEDIUM 5.3 CVE-2022-43434 Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protection for user-generated conte… Neuvector Vulnerability Scanner after 1.20 Fix from $1,6002022-10-19 MEDIUM 5.3 CVE-2022-43435 Jenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, … 360 Fireline after 1.7.2 Fix from $1,6002022-10-19