Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2022-34791 Jenkins Validating Email Parameter Plugin 1.10 and earlier does not escape the name and description of its parameter type, resulting in a stored cros… Validating Email Parameter after 1.10 Fix from $1,6002022-06-30 MEDIUM 5.4 CVE-2022-34795 Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard view, resulting in a stored cros… Deployment Dashboard after 1.0.10 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34789 A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix bui… Matrix Reloaded after 1.1.3 Fix from $1,6002022-06-30 MEDIUM 5.4 CVE-2022-34786 Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resulting in a stored cross-site scri… Rich Text Publisher after 1.4 Fix from $1,6002022-06-30 MEDIUM 5.4 CVE-2022-34787 Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scriptin… Project Inheritance after 21.04.03 Fix from $1,6002022-06-30 MEDIUM 5.4 CVE-2022-34788 Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnera… Matrix Reloaded after 1.1.3 Fix from $1,6002022-06-30 MEDIUM 5.4 CVE-2022-34790 Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a stored cross-site scripting (X… Extreme Feedback Panel after 2.0.1 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34780 A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacke… Xebialabs Xl Release after 22.0.0 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34781 Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an att… Xebialabs Xl Release after 22.0.0 Fix from $1,6002022-06-30 MEDIUM 5.4 CVE-2022-34783EPSS 81% Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable … Plot after 2.1.10 Fix from $1,6002022-06-30 MEDIUM 5.4 CVE-2022-34784 Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-site scripting (XSS) vulnerab… Build Metrics Mitigation only Fix from $1,6002022-06-30 MEDIUM 5.4 CVE-2022-34777EPSS 72% Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-triggered builds, resulting in a st… GitLab after 1.5.34 Fix from $1,6002022-06-30 MEDIUM 5.4 CVE-2022-34778 Jenkins TestNG Results Plugin 554.va4a552116332 and earlier renders the unescaped test descriptions and exception messages provided in test results i… Testng Results after 554.va4a552116332 Fix from $1,6002022-06-30 MEDIUM 6.5 CVE-2022-34213 Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file on the Jenkins co… Squash Tm Publisher after 1.0.0 Fix from $1,6002022-06-23 MEDIUM 5.7 CVE-2022-34212 A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST… Vrealize Orchestrator after 3.0 Fix from $1,6002022-06-23 HIGH 8.8 CVE-2022-34200 A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers to connect to an atta… Convertigo Mobile Platform after 1.1 Fix from $1,9502022-06-23 HIGH 8.8 CVE-2022-34203 A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect to an attacker-specified HTTP … Easyqa after 1.0 Fix from $1,9502022-06-23 MEDIUM 6.5 CVE-2022-34199 Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they c… Convertigo Mobile Platform after 1.1 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34201 A missing permission check in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to a… Convertigo Mobile Platform after 1.1 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34202 Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be … Easyqa after 1.0 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34205 A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests… Jianliao Notification after 1.1 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34207 A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specif… Beaker Builder after 1.10 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34209 A cross-site request forgery (CSRF) vulnerability in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers to connect to an attacker-specified … Threadfix after 1.5.4 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34210 A missing permission check in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-spec… Threadfix after 1.5.4 Fix from $1,6002022-06-23 MEDIUM 6.5 CVE-2022-34211 A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers to send an HTTP POST reque… Vrealize Orchestrator after 3.0 Fix from $1,6002022-06-23 MEDIUM 5.4 CVE-2022-34198 Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier does not escape the name and description of Stash Branch parameters on views displaying param… Stash Branch Parameter after 0.3.0 Fix from $1,6002022-06-23 MEDIUM 5.4 CVE-2022-34183 Jenkins Agent Server Parameter Plugin 1.1 and earlier does not escape the name and description of Agent Server parameters on views displaying paramet… Agent Server Parameter after 1.1 Fix from $1,6002022-06-23 MEDIUM 5.4 CVE-2022-34184 Jenkins CRX Content Package Deployer Plugin 1.9 and earlier does not escape the name and description of CRX Content Package Choice parameters on view… Crx Content Package Deployer after 1.9 Fix from $1,6002022-06-23 MEDIUM 5.4 CVE-2022-34185 Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting… Date Parameter after 0.0.4 Fix from $1,6002022-06-23 MEDIUM 5.4 CVE-2022-34186 Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape the name and description of Moded Extended Choice parameters on vi… Dynamic Extended Choice Parameter after 1.0.1 Fix from $1,6002022-06-23