Vulnerability index

Browse CVEs

1,321 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2022-25191 Jenkins Agent Server Parameter Plugin 1.0 and earlier does not escape parameter names of agent server parameters, resulting in a stored cross-site sc… Agent Server Parameter after 1.0 Fix from $1,6002022-02-15 MEDIUM 5.4 CVE-2022-25196 Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication pro… Gitlab Authentication after 1.13 Fix from $1,6002022-02-15 MEDIUM 5.4 CVE-2022-25203 Jenkins Team Views Plugin 0.9.0 and earlier does not escape team names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by… Team Views after 0.9.0 Fix from $1,6002022-02-15 HIGH 8.8 CVE-2022-25181 A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure… Pipeline\ after 552.vd9cc05b8a2e1 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25182 A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure… Pipeline\ after 552.vd9cc05b8a2e1 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25183 Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories witho… Pipeline\ after 552.vd9cc05b8a2e1 Fix from $1,9502022-02-15 MEDIUM 6.5 CVE-2022-25184 Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipeline script using the Pipeline S… Pipeline\ after 2.15 Fix from $1,6002022-02-15 MEDIUM 6.5 CVE-2022-25186 Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the ag… Hashicorp Vault after 3.8.0 Fix from $1,6002022-02-15 MEDIUM 6.5 CVE-2022-25187 Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle. Support Core after 2.79 Fix from $1,6002022-02-15 MEDIUM 5.4 CVE-2022-25185 Jenkins Generic Webhook Trigger Plugin 1.81 and earlier does not escape the build cause when using the webhook, resulting in a stored cross-site scri… Generic Webhook Trigger after 1.81 Fix from $1,6002022-02-15 MEDIUM 5.4 CVE-2022-25189 Jenkins Custom Checkbox Parameter Plugin 1.1 and earlier does not escape parameter names of custom checkbox parameters, resulting in a stored cross-s… Custom Checkbox Parameter after 1.1 Fix from $1,6002022-02-15 HIGH 8.8 CVE-2022-25173 Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typ… Pipeline\ after 2648.va9433432b33c Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25174 Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libr… Pipeline\ after 552.vd9cc05b8a2e1 Fix from $1,9502022-02-15 HIGH 8.8 CVE-2022-25175 Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, all… Pipeline\ after 706.vd43c65dec013 Fix from $1,9502022-02-15 MEDIUM 6.5 CVE-2022-25176 Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checkout directory for the configur… Pipeline\ after 2648.va9433432b33c Fix from $1,6002022-02-15 MEDIUM 6.5 CVE-2022-25177 Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic links to locations outside of the expected Pipeline l… Pipeline\ after 552.vd9cc05b8a2e1 Fix from $1,6002022-02-15 MEDIUM 6.5 CVE-2022-25178 Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier does not restrict the names of resources passed to the libraryResource… Pipeline\ after 552.vd9cc05b8a2e1 Fix from $1,6002022-02-15 MEDIUM 6.5 CVE-2022-25179 Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the checkout directory for the conf… Pipeline\ after 706.vd43c65dec013 Fix from $1,6002022-02-15 HIGH 7.5 CVE-2022-0538 Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vuln… Jenkins 2.319.3 / 2.334+ Fix from $1,9502022-02-09 HIGH 7.5 CVE-2021-43859EPSS 8% XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 1… Jenkins 1.4.19 / 2.319.3+ Fix from $1,9502022-02-01 HIGH 8.8 CVE-2022-23118 Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-spec… Debian Package Builder after 1.6.11 Fix from $1,9502022-01-12 HIGH 8.1 CVE-2022-23107 Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with I… Warnings Next Generation 9.0.2 / 9.5.2+ Fix from $1,9502022-01-12 HIGH 7.5 CVE-2022-23116 Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets sto… Conjur Secrets after 1.0.9 Fix from $1,9502022-01-12 HIGH 7.5 CVE-2022-23117 Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all userna… Conjur Secrets after 1.0.9 Fix from $1,9502022-01-12 HIGH 7.1 CVE-2022-20619 A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect… Bitbucket Branch Source after 2.9.10 Fix from $1,9502022-01-12 MEDIUM 6.5 CVE-2022-23105 Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory server… Active Directory after 2.25 Fix from $1,6002022-01-12 MEDIUM 6.5 CVE-2022-23109 Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipelin… Hashicorp Vault after 3.7.0 Fix from $1,6002022-01-12 MEDIUM 6.5 CVE-2022-23112 A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access to connect to an attacker-sp… Publish Over Ssh after 1.22 Fix from $1,6002022-01-12 MEDIUM 5.5 CVE-2022-20621 Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can b… Metrics after 4.0.2.8 Fix from $1,6002022-01-12 MEDIUM 5.4 CVE-2022-23108 Jenkins Badge Plugin 1.9 and earlier does not escape the description and does not check for allowed protocols when creating a badge, resulting in a s… Badge after 1.9 Fix from $1,6002022-01-12