jenkins
1,755 tracked vulnerabilities.
CVE-2022-34801
MEDIUM
Jenkins Build Notifications Plugin < 1.5.0 - Cleartext Transmission of Sensitive Tokens
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34800
MEDIUM
Jenkins Build Notifications Plugin <= 1.5.0 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34799
MEDIUM
Jenkins Deployment Dashboard Plugin <= 1.0.10 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34798
MEDIUM
Jenkins Deployment Dashboard < 1.0.10 - Missing Authorization in HTTP Endpoints
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34797
MEDIUM
Jenkins Deployment Dashboard Plugin < 1.0.10 - Cross-Site Request Forgery
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34796
MEDIUM
Jenkins Deployment Dashboard < 1.0.10 - Credential ID Enumeration via Missing Authorization
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34795
MEDIUM
Jenkins Deployment Dashboard Plugin <= 1.0.10 - Stored Cross-Site Scripting in Environment Names
Jun 30, 2022
CVSS 5.4
EPSS 0.09
CVE-2022-34794
MEDIUM
Jenkins Recipe Plugin < 1.2 - Server-Side Request Forgery via XML Response Parsing
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34793
HIGH
Jenkins Recipe Plugin < 1.2 - XML External Entity Injection
Jun 30, 2022
CVSS 8.8
EPSS 0.01
CVE-2022-34792
HIGH
Jenkins Recipe Plugin < 1.2 - Cross-Site Request Forgery
Jun 30, 2022
CVSS 8.0
EPSS 0.00
CVE-2022-34791
MEDIUM
Jenkins Validating Email Parameter Plugin < 1.10 - Stored Cross-Site Scripting in Parameter Name and Description
Jun 30, 2022
CVSS 5.4
EPSS 0.09
CVE-2022-34790
MEDIUM
Jenkins eXtreme Feedback Panel Plugin < 2.0.1 - Stored Cross-Site Scripting in Job Name Tooltips
Jun 30, 2022
CVSS 5.4
EPSS 0.08
CVE-2022-34789
MEDIUM
Jenkins Matrix Reloaded Plugin < 1.1.3 - Cross-Site Request Forgery
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34788
MEDIUM
Jenkins Matrix Reloaded Plugin <= 1.1.3 - Stored Cross-Site Scripting in Agent Name Tooltip
Jun 30, 2022
CVSS 5.4
EPSS 0.09
CVE-2022-34787
MEDIUM
Jenkins Project Inheritance Plugin < 21.04.03 - Cross-Site Scripting in Build Blocked Reason Tooltip
Jun 30, 2022
CVSS 5.4
EPSS 0.09
CVE-2022-34786
MEDIUM
Jenkins Rich Text Publisher Plugin < 1.4 - Stored Cross-Site Scripting in HTML Message
Jun 30, 2022
CVSS 5.4
EPSS 0.09
CVE-2022-34785
MEDIUM
Jenkins build-metrics < 1.3 - Incorrect Authorization in HTTP Endpoints
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34784
MEDIUM
Jenkins build-metrics 1.3 - Stored Cross-Site Scripting in Build Description View
Jun 30, 2022
CVSS 5.4
EPSS 0.09
CVE-2022-34783
MEDIUM
Jenkins Plot Plugin < 2.1.10 - Stored Cross-Site Scripting in Plot Descriptions
Jun 30, 2022
CVSS 5.4
EPSS 0.32
CVE-2022-34782
MEDIUM
Jenkins requests-plugin < 2.2.16 - Incorrect Authorization
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34781
MEDIUM
Jenkins XebiaLabs XL Release Plugin < 22.0.0 - Missing Authorization
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34780
MEDIUM
Jenkins XebiaLabs XL Release Plugin < 22.0.0 - Cross-Site Request Forgery
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34779
MEDIUM
Jenkins XebiaLabs XL Release Plugin < 22.0.1 - Missing Authorization for Credential ID Enumeration
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34778
MEDIUM
Jenkins TestNG Results Plugin < 554.va4a552116332 - Cross-Site Scripting via Unescaped Test Descriptions
Jun 30, 2022
CVSS 5.4
EPSS 0.09
CVE-2022-34777
MEDIUM
Jenkins GitLab Plugin < 1.5.34 - Stored Cross-Site Scripting in Webhook Build Description
Jun 30, 2022
CVSS 5.4
EPSS 0.15
Products
jenkins 259
pipeline\ 37
script_security 33
blue_ocean 11
git 11
email_extension 10
active_directory 9
build_failure_analyzer 9
config_file_provider 9
configuration_as_code 9
ns-nd_integration_performance_publisher 8
credentials_binding 7
github_branch_source 7
html_publisher 7
kubernetes 7
openid_connect_authentication 7
openshift_deployer 7
rundeck 7
subversion 7
amazon_ec2 6
azure_ad 6
azure_vm_agents 6
deployment_dashboard 6
electricflow 6
gerrit_trigger 6
github 6
github_pull_request_builder 6
gitlab 6
google_compute_engine 6
hashicorp_vault 6
Quick Filters