Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2022-25191
Jenkins Agent Server Parameter Plugin 1.0 and earlier does not escape parameter names of agent server parameters, resulting in a stored cross-site sc…
Agent Server Parameter
after 1.0
MEDIUM 5.4
CVE-2022-25196
Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication pro…
Gitlab Authentication
after 1.13
MEDIUM 5.4
CVE-2022-25203
Jenkins Team Views Plugin 0.9.0 and earlier does not escape team names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by…
Team Views
after 0.9.0
HIGH 8.8
CVE-2022-25181
A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure…
Pipeline\
after 552.vd9cc05b8a2e1
HIGH 8.8
CVE-2022-25182
A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure…
Pipeline\
after 552.vd9cc05b8a2e1
HIGH 8.8
CVE-2022-25183
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories witho…
Pipeline\
after 552.vd9cc05b8a2e1
MEDIUM 6.5
CVE-2022-25184
Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipeline script using the Pipeline S…
Pipeline\
after 2.15
MEDIUM 6.5
CVE-2022-25186
Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Vault secrets for use on the ag…
Hashicorp Vault
after 3.8.0
MEDIUM 6.5
CVE-2022-25187
Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.
Support Core
after 2.79
MEDIUM 5.4
CVE-2022-25185
Jenkins Generic Webhook Trigger Plugin 1.81 and earlier does not escape the build cause when using the webhook, resulting in a stored cross-site scri…
Generic Webhook Trigger
after 1.81
MEDIUM 5.4
CVE-2022-25189
Jenkins Custom Checkbox Parameter Plugin 1.1 and earlier does not escape parameter names of custom checkbox parameters, resulting in a stored cross-s…
Custom Checkbox Parameter
after 1.1
HIGH 8.8
CVE-2022-25173
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typ…
Pipeline\
after 2648.va9433432b33c
HIGH 8.8
CVE-2022-25174
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libr…
Pipeline\
after 552.vd9cc05b8a2e1
HIGH 8.8
CVE-2022-25175
Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, all…
Pipeline\
after 706.vd43c65dec013
MEDIUM 6.5
CVE-2022-25176
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checkout directory for the configur…
Pipeline\
after 2648.va9433432b33c
MEDIUM 6.5
CVE-2022-25177
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic links to locations outside of the expected Pipeline l…
Pipeline\
after 552.vd9cc05b8a2e1
MEDIUM 6.5
CVE-2022-25178
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier does not restrict the names of resources passed to the libraryResource…
Pipeline\
after 552.vd9cc05b8a2e1
MEDIUM 6.5
CVE-2022-25179
Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the checkout directory for the conf…
Pipeline\
after 706.vd43c65dec013
HIGH 7.5
CVE-2022-0538
Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vuln…
Jenkins
2.319.3 / 2.334+
HIGH 7.5
CVE-2021-43859EPSS 8%
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 1…
Jenkins
1.4.19 / 2.319.3+
HIGH 8.8
CVE-2022-23118
Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-spec…
Debian Package Builder
after 1.6.11
HIGH 8.1
CVE-2022-23107
Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with I…
Warnings Next Generation
9.0.2 / 9.5.2+
HIGH 7.5
CVE-2022-23116
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets sto…
Conjur Secrets
after 1.0.9
HIGH 7.5
CVE-2022-23117
Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all userna…
Conjur Secrets
after 1.0.9
HIGH 7.1
CVE-2022-20619
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect…
Bitbucket Branch Source
after 2.9.10
MEDIUM 6.5
CVE-2022-23105
Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory server…
Active Directory
after 2.25
MEDIUM 6.5
CVE-2022-23109
Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipelin…
Hashicorp Vault
after 3.7.0
MEDIUM 6.5
CVE-2022-23112
A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access to connect to an attacker-sp…
Publish Over Ssh
after 1.22
MEDIUM 5.5
CVE-2022-20621
Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can b…
Metrics
after 4.0.2.8
MEDIUM 5.4
CVE-2022-23108
Jenkins Badge Plugin 1.9 and earlier does not escape the description and does not check for allowed protocols when creating a badge, resulting in a s…
Badge
after 1.9