Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2022-27204 A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers to connect to … Extended Choice Parameter after 346.vd87693c5a_86c Fix from $1,9502022-03-15 MEDIUM 6.5 CVE-2022-27206 Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins contro… Gitlab Authentication after 1.13 Fix from $1,6002022-03-15 MEDIUM 6.5 CVE-2022-27208 Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read arbitrary files on the Jenkins … Kubernetes Continuous Deploy after 2.3.1 Fix from $1,6002022-03-15 MEDIUM 6.5 CVE-2022-27209 A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerat… Kubernetes Continuous Deploy after 2.3.1 Fix from $1,6002022-03-15 MEDIUM 6.5 CVE-2022-27210 A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an … Kubernetes Continuous Deploy after 2.3.1 Fix from $1,6002022-03-15 MEDIUM 6.5 CVE-2022-27211 A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect … Kubernetes Continuous Deploy after 2.3.1 Fix from $1,6002022-03-15 HIGH 8.0 CVE-2022-27198 A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Ove… Cloudbees Aws Credentials 1.28.2+ Fix from $1,9502022-03-15 MEDIUM 6.5 CVE-2022-27201 Jenkins Semantic Versioning Plugin 1.13 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitatio… Semantic Versioning after 1.13 Fix from $1,6002022-03-15 MEDIUM 6.5 CVE-2022-27203 Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Item/Configure permission to read values from arbitrary… Extended Choice Parameter after 346.vd87693c5a_86c Fix from $1,6002022-03-15 MEDIUM 5.4 CVE-2022-27197 Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source URL, resulting in a stored cros… Dashboard View 2.18.1+ Fix from $1,6002022-03-15 MEDIUM 5.4 CVE-2022-27202 Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value and description of extended choice parameters of ra… Extended Choice Parameter after 346.vd87693c5a_86c Fix from $1,6002022-03-15 MEDIUM 5.5 CVE-2022-27195 Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger P… Parameterized Trigger 2.43.1+ Fix from $1,6002022-03-15 MEDIUM 5.4 CVE-2022-27196 Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a stored cross-site scripting (XSS) … Favorite 2.4.1+ Fix from $1,6002022-03-15 HIGH 8.8 CVE-2022-25205 A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified d… Dbcharts after 0.5.2 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25206 A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified databa… Dbcharts after 0.5.2 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25207 A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP reque… Chef Sinatra after 1.20 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25208 A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP… Chef Sinatra after 1.20 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25209 Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Chef Sinatra after 1.20 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25211 A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specifie… Swamp after 1.2.6 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25212 A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect to an attacker-specified web … Swamp after 1.2.6 Fix from $1,9502022-02-15 MEDIUM 6.5 CVE-2022-25210 Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier uses static fields to store job configuration information, allowing attackers with Item/Con… Convertigo Mobile Platform after 1.1 Fix from $1,6002022-02-15 MEDIUM 5.4 CVE-2022-25204 Jenkins Doktor Plugin 0.4.1 and earlier implements functionality that allows agent processes to render files on the controller as Markdown or Asciido… Doktor after 0.4.1 Fix from $1,6002022-02-15 HIGH 8.8 CVE-2022-25192 A cross-site request forgery (CSRF) vulnerability in Jenkins Snow Commander Plugin 1.10 and earlier allows attackers to connect to an attacker-specif… Snow Commander after 1.10 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25194 A cross-site request forgery (CSRF) vulnerability in Jenkins autonomiq Plugin 1.15 and earlier allows attackers to connect to an attacker-specified U… Autonomiq after 1.15 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25198 A cross-site request forgery (CSRF) vulnerability in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers to connect to an attacker-specifie… Scp Publisher after 1.8 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25199 A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-sp… Scp Publisher after 1.8 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25200 A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specifi… Checkmarx after 2022.1.2 Fix from $1,9502022-02-15 MEDIUM 6.5 CVE-2022-25193 Missing permission checks in Jenkins Snow Commander Plugin 1.10 and earlier allow attackers with Overall/Read permission to connect to an attacker-sp… Snow Commander after 1.10 Fix from $1,6002022-02-15 MEDIUM 6.5 CVE-2022-25197 Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements functionality that allows agent processes to read arbitrary files on the Jenk… Hashicorp Vault after 336.v182c0fbaaeb7 Fix from $1,6002022-02-15 MEDIUM 6.5 CVE-2022-25201 Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-spe… Checkmarx after 2022.1.2 Fix from $1,6002022-02-15