Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2022-41246 A missing permission check in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers with Overall/Read permission to conne… Worksoft Execution Manager after 10.0.3.503 Fix from $1,6002022-09-21 MEDIUM 6.5 CVE-2022-41250 A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-s… Scm Httpclient after 1.5 Fix from $1,6002022-09-21 MEDIUM 6.5 CVE-2022-41254 Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specifie… Cons3rt after 1.0.0 Fix from $1,6002022-09-21 MEDIUM 6.5 CVE-2022-41255 Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it can be viewe… Cons3rt after 1.0.0 Fix from $1,6002022-09-21 MEDIUM 5.3 CVE-2022-41248 Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potential for … Bigpanda Notifier after 1.4.0 Fix from $1,6002022-09-21 CRITICAL 9.8 CVE-2022-41237 Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote co… Dotci after 2.40.00 Fix from $2,3002022-09-21 CRITICAL 9.8 CVE-2022-41238 A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to th… Dotci after 2.40.00 Fix from $2,3002022-09-21 CRITICAL 9.1 CVE-2022-41241 Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Rqm after 2.8 Fix from $2,3002022-09-21 HIGH 8.8 CVE-2022-41227 A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to… Ns Nd Integration Performance Publisher 4.8.0.130+ Fix from $1,9502022-09-21 HIGH 8.8 CVE-2022-41228 A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permiss… Ns Nd Integration Performance Publisher 4.8.0.130+ Fix from $1,9502022-09-21 HIGH 8.8 CVE-2022-41234 Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing users with Overall/Read permissi… Rundeck after 3.6.11 Fix from $1,9502022-09-21 HIGH 8.8 CVE-2022-41236 A cross-site request forgery (CSRF) vulnerability in Jenkins Security Inspector Plugin 117.v6eecc36919c2 and earlier allows attackers to replace the … Security Inspector after 117.v6eecc36919c2 Fix from $1,9502022-09-21 HIGH 8.1 CVE-2022-41243 Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused … Smalltest after 1.0.4 Fix from $1,9502022-09-21 HIGH 8.0 CVE-2022-41232 A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers to replace any config.xml file … Build Publisher after 1.22 Fix from $1,9502022-09-21 MEDIUM 5.7 CVE-2022-41231 Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenki… Build Publisher after 1.22 Fix from $1,6002022-09-21 MEDIUM 5.4 CVE-2022-41229 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud T… Ns Nd Integration Performance Publisher after 4.8.0.134 Fix from $1,6002022-09-21 MEDIUM 5.4 CVE-2022-41239 Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a bu… Dotci after 2.40.00 Fix from $1,6002022-09-21 MEDIUM 5.4 CVE-2022-41240 Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vu… Walti after 1.0.1 Fix from $1,6002022-09-21 MEDIUM 5.4 CVE-2022-41242 A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information a… Extreme Feedback after 1.7 Fix from $1,6002022-09-21 MEDIUM 5.3 CVE-2022-41235 Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenkins control… Wildfly Deployer after 1.0.2 Fix from $1,6002022-09-21 CRITICAL 9.8 CVE-2022-41226 Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Compuware Common Configuration 1.0.15+ Fix from $2,3002022-09-21 MEDIUM 5.4 CVE-2022-41224 Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, … Jenkins 2.370+ Fix from $1,6002022-09-21 MEDIUM 5.4 CVE-2022-41225 Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine API, resulting in a stored c… Anchore Container Image Scanner 1.0.25+ Fix from $1,6002022-09-21 MEDIUM 6.5 CVE-2022-38663 Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username… Git after 4.11.4 Fix from $1,6002022-08-23 MEDIUM 6.5 CVE-2022-38665 Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller … Collabnet after 2.0.8 Fix from $1,6002022-08-23 MEDIUM 5.4 CVE-2022-38664 Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, result… Job Configuration History after 1165.v8cc9fd1f4597 Fix from $1,6002022-08-23 HIGH 8.8 CVE-2022-36920 A cross-site request forgery (CSRF) vulnerability in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified … Coverity after 1.11.4 Fix from $1,9502022-07-27 HIGH 8.1 CVE-2022-36921 A missing permission check in Jenkins Coverity Plugin 1.11.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec… Coverity after 1.11.4 Fix from $1,9502022-07-27 MEDIUM 6.1 CVE-2022-36922 Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page, resultin… Lucene Search after 370.v62a5f618cd3a Fix from $1,6002022-07-27 HIGH 8.0 CVE-2022-36916 A cross-site request forgery (CSRF) vulnerability in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers to request a manual backup. Google Cloud Backup after 0.6 Fix from $1,9502022-07-27