jenkins

1,755 tracked vulnerabilities.

CVE-2022-36887 MEDIUM
Jenkins Job Configuration History Plugin < 1155.v28a_46a_cc06a_5 - Cross-Site Request Forgery
Jul 27, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-36886 MEDIUM
Jenkins External Monitor Job Type Plugin < 191.v363d0d1efdf8 - Cross-Site Request Forgery
Jul 27, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-36885 MEDIUM
Jenkins GitHub Plugin < 1.34.4 - Timing Attack via Webhook Signature Comparison
Jul 27, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-36884 MEDIUM
Jenkins Git Plugin < 4.11.3 - Unauthenticated Information Disclosure via Webhook Endpoint
Jul 27, 2022
CVSS 5.3
EPSS 0.01
CVE-2022-36883 HIGH NUCLEI
Jenkins Git Plugin < 4.11.3 - Unauthenticated Build Trigger and Arbitrary Repository Checkout
Jul 27, 2022
CVSS 7.5
EPSS 0.81
CVE-2022-36882 HIGH
Jenkins Git Plugin < 4.11.3 - Cross-Site Request Forgery
Jul 27, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-36881 HIGH
Jenkins Git client Plugin <= 3.11.0 - SSH Host Key Verification Bypass
Jul 27, 2022
CVSS 8.1
EPSS 0.01
CVE-2022-2048 HIGH
Eclipse Jetty < 9.4.47 - Denial of Service via HTTP/2 Request Error Handling
Jul 07, 2022
CVSS 7.5
EPSS 0.01
CVE-2022-34818 MEDIUM
Jenkins Failed Job Deactivator Plugin <= 1.2.1 - Missing Authorization in Views and HTTP Endpoints
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34817 MEDIUM
Jenkins Failed Job Deactivator Plugin < 1.2.1 - Cross-Site Request Forgery
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34816 MEDIUM
Jenkins HPE Network Virtualization Plugin 1.0 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34815 MEDIUM
Jenkins Request Rename Or Delete Plugin < 1.1.0 - Cross-Site Request Forgery
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34814 MEDIUM
Jenkins Request Rename Or Delete Plugin < 1.1.0 - Unauthorized Access to Administrative Configuration Page
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34813 MEDIUM
Jenkins XPath Configuration Viewer Plugin < 1.1.1 - Missing Authorization for XPath Expression Management
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34812 MEDIUM
Jenkins XPath Configuration Viewer Plugin < 1.1.1 - Cross-Site Request Forgery
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34811 MEDIUM
Jenkins XPath Configuration Viewer Plugin < 1.1.1 - Missing Authorization
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34810 MEDIUM
Jenkins RQM Plugin < 2.8 - Credential ID Enumeration via Overall/Read Permission
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34809 MEDIUM
Jenkins RQM Plugin < 2.8 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34808 MEDIUM
Jenkins Cisco Spark Plugin < 1.1.1 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34807 MEDIUM
Jenkins Elasticsearch Query Plugin <= 1.2 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34806 MEDIUM
Jenkins Jigomerge < 0.9 - Insufficiently Protected Credentials in Job Config Files
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34805 MEDIUM
Jenkins Skype notifier Plugin < 1.1.0 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34804 MEDIUM
Jenkins OpsGenie Plugin < 1.9 - Cleartext Transmission of Sensitive Information via Configuration Forms
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34803 MEDIUM
Jenkins OpsGenie Plugin < 1.9 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34802 MEDIUM
Jenkins RocketChat Notifier Plugin <= 1.5.2 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 4.3
EPSS 0.00