Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2022-36906 A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to connect to an attacker-s… Openshift Deployer after 1.2.0 Fix from $1,6002022-07-27 MEDIUM 6.5 CVE-2022-36907 A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to connect to an atta… Openshift Deployer after 1.2.0 Fix from $1,6002022-07-27 MEDIUM 6.5 CVE-2022-36908 A cross-site request forgery (CSRF) vulnerability in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers to check for the existence … Openshift Deployer after 1.2.0 Fix from $1,6002022-07-27 MEDIUM 6.5 CVE-2022-36909 A missing permission check in Jenkins OpenShift Deployer Plugin 1.2.0 and earlier allows attackers with Overall/Read permission to check for the exis… Openshift Deployer after 1.2.0 Fix from $1,6002022-07-27 MEDIUM 6.5 CVE-2022-36911 A cross-site request forgery (CSRF) vulnerability in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers to connect to an attacker-specifi… Openstack Heat after 1.5 Fix from $1,6002022-07-27 MEDIUM 5.4 CVE-2022-36905 Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven … Maven Metadata after 2.2 Fix from $1,6002022-07-27 MEDIUM 5.4 CVE-2022-36910 Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Ove… Lucene Search after 370.v62a5f618cd3a Fix from $1,6002022-07-27 HIGH 8.8 CVE-2022-36889 Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployme… Deployer Framework after 85.v1d1888e8c021 Fix from $1,9502022-07-27 HIGH 8.2 CVE-2022-36899 Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers ab… Compuware Ispw Operations 1.0.9+ Fix from $1,9502022-07-27 HIGH 8.2 CVE-2022-36900 Jenkins Compuware zAdviser API Plugin 1.0.3 and earlier does not restrict execution of a controller/agent message to agents, allowing attackers able … Compuware Zadviser Api after 1.0.3 Fix from $1,9502022-07-27 MEDIUM 6.5 CVE-2022-36888 A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overall/Read permission to obtain … Hashicorp Vault after 354.vdb_858fd6b_f48 Fix from $1,6002022-07-27 MEDIUM 6.5 CVE-2022-36894 An arbitrary file write vulnerability in Jenkins CLIF Performance Testing Plugin 64.vc0d66de1dfb_f and earlier allows attackers with Overall/Read per… Clif Performance Testing after 64.vc0d66de1dfb_f Fix from $1,6002022-07-27 MEDIUM 6.5 CVE-2022-36896 A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier allows attackers with Overa… Compuware Source Code Download For Endevor\, Pds\, And Ispw after 2.0.12 Fix from $1,6002022-07-27 MEDIUM 6.5 CVE-2022-36901 Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller whe… Http Request after 1.15 Fix from $1,6002022-07-27 MEDIUM 5.4 CVE-2022-36902 Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape several fields of Moded Extended Choice parameters, resulting in a… Dynamic Extended Choice Parameter after 1.0.1 Fix from $1,6002022-07-27 HIGH 8.8 CVE-2022-36882 A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger builds of jobs configured to u… Git after 4.11.3 Fix from $1,9502022-07-27 HIGH 8.1 CVE-2022-36881 Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositories via SSH, enabling man-in-… Git Client after 3.11.0 Fix from $1,9502022-07-27 HIGH 7.5 CVE-2022-36883EPSS 6% A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an a… Git after 4.11.3 Fix from $1,9502022-07-27 MEDIUM 5.3 CVE-2022-36884 The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to… Git after 4.11.3 Fix from $1,6002022-07-27 MEDIUM 5.3 CVE-2022-36885 Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided and computed webhook signatu… GitHub after 1.34.4 Fix from $1,6002022-07-27 MEDIUM 6.5 CVE-2015-5298 The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are suppo… Google Login Mitigation only Fix from $1,6002022-07-07 MEDIUM 6.5 CVE-2022-34810 A missing check in Jenkins RQM Plugin 2.8 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials store… Rqm after 2.8 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34816 Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can … Hpe Network Virtualization Mitigation only Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34805 Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can… Skype Notifier after 1.1.0 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34806 Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by u… Jigomerge after 0.9 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34807 Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it … Elasticsearch Query after 1.2 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34809 Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by… Rqm after 2.8 Fix from $1,6002022-06-30 HIGH 8.8 CVE-2022-34793 Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Recipe after 1.2 Fix from $1,9502022-06-30 HIGH 8.0 CVE-2022-34792 A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an HTTP request to an attacker-sp… Recipe after 1.2 Fix from $1,9502022-06-30 MEDIUM 6.5 CVE-2022-34794 Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacke… Recipe after 1.2 Fix from $1,6002022-06-30