org.jenkins-ci.plugins
1,024 tracked vulnerabilities.
CVE-2023-24422
HIGH
Jenkins Script Security Plugin <1228.vd93135a_2fb_25 - Sandbox Bypass via Map Constructors
Jan 26, 2023
CVSS 8.8
EPSS 0.00
CVE-2022-46688
MEDIUM
Jenkins Sonar Gerrit Plugin <377.v8f3808963dc5 - CSRF
Dec 12, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-46685
MEDIUM
Jenkins Gitea Plugin <1.4.4 - Info Disclosure
Dec 12, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-46683
MEDIUM
Jenkins Google Login Plugin <1.7 - Open Redirect
Dec 12, 2022
CVSS 6.1
EPSS 0.01
CVE-2022-46682
CRITICAL
Jenkins Plot Plugin < 2.1.12 - XML External Entity Injection
Dec 12, 2022
CVSS 9.8
EPSS 0.02
CVE-2022-45394
MEDIUM
Jenkins Delete log Plugin < 1.0 - Missing Authorization for Build Log Deletion
Nov 15, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-45393
LOW
Jenkins Delete log Plugin < 1.0 - Cross-Site Request Forgery
Nov 15, 2022
CVSS 3.5
EPSS 0.00
CVE-2022-45387
MEDIUM
Jenkins BART Plugin < 1.0.3 - Stored Cross-Site Scripting in Build Log Renderer
Nov 15, 2022
CVSS 5.4
EPSS 0.05
CVE-2022-45386
MEDIUM
Jenkins Violations Plugin < 0.7.11 - XML External Entity Injection
Nov 15, 2022
CVSS 5.5
EPSS 0.02
CVE-2022-45385
HIGH
Jenkins CloudBees Docker Hub/Registry Notification Plugin < 2.6.2.1 - Unauthenticated Build Trigger
Nov 15, 2022
CVSS 7.5
EPSS 0.02
CVE-2022-45383
MEDIUM
Jenkins Support Core Plugin < 1206.1208.v9b_7a_1d48db_0f - Incorrect Authorization
Nov 15, 2022
CVSS 6.5
EPSS 0.01
CVE-2022-45382
MEDIUM
Jenkins Naginator Plugin < 1.18.2 - Stored Cross-Site Scripting via Build Display Name
Nov 15, 2022
CVSS 5.4
EPSS 0.09
CVE-2022-45381
HIGH
Jenkins Pipeline Utility Steps < 2.13.2 - Arbitrary File Read via Apache Commons Configuration Interpolator
Nov 15, 2022
CVSS 8.1
EPSS 0.00
CVE-2022-45380
MEDIUM
Jenkins JUnit Plugin < 1160.vf1f01a_a_ea_b_7f - Stored Cross-Site Scripting via Test Report URL Conversion
Nov 15, 2022
CVSS 5.4
EPSS 0.02
CVE-2022-45379
HIGH
Jenkins Script Security Plugin < 1190.v65867a_a_47126 - Inadequate Encryption Strength via SHA-1 Hash Collision
Nov 15, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-43432
MEDIUM
Jenkins XFramium Builder Plugin <1.0.22 - XSS
Oct 19, 2022
CVSS 4.3
EPSS 0.01
CVE-2022-43421
MEDIUM
Jenkins Tuleap Git Branch Source Plugin <3.2.4 - Info Disclosure
Oct 19, 2022
CVSS 5.3
EPSS 0.03
CVE-2022-43420
MEDIUM
Jenkins Contrast Plugin < 3.10 - Stored XSS via API Data
Oct 19, 2022
CVSS 5.4
EPSS 0.12
CVE-2022-43419
MEDIUM
Jenkins Katalon Plugin <1.0.32 - Info Disclosure
Oct 19, 2022
CVSS 6.5
EPSS 0.01
CVE-2022-43418
MEDIUM
Jenkins Katalon Plugin <1.0.33 - CSRF
Oct 19, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-43417
MEDIUM
Jenkins Katalon Plugin <1.0.32 - Open Redirect
Oct 19, 2022
CVSS 4.3
EPSS 0.01
CVE-2022-43416
HIGH
Jenkins Katalon Plugin <1.0.32 - RCE
Oct 19, 2022
CVSS 8.8
EPSS 0.03
CVE-2022-43415
HIGH
Jenkins REPO Plugin < 1.16.0 - XML External Entity Injection
Oct 19, 2022
CVSS 7.5
EPSS 0.06
CVE-2022-43414
MEDIUM
Jenkins NUnit Plugin <0.27 - Info Disclosure
Oct 19, 2022
CVSS 5.3
EPSS 0.01
CVE-2022-43413
MEDIUM
Jenkins Job Import Plugin <3.5 - Info Disclosure
Oct 19, 2022
CVSS 4.3
EPSS 0.01
Products
script-security 35
git 13
email-ext 11
active-directory 9
config-file-provider 9
electricflow 9
ec2 8
oic-auth 8
subversion 8
artifactory 7
credentials-binding 7
htmlpublisher 7
jobConfigHistory 7
mercurial 7
openshift-deployer 7
rundeck 7
azure-ad 6
azure-vm-agents 6
ec2-deployment-dashboard 6
fortify-on-demand-uploader 6
ghprb 6
gitlab-oauth 6
gitlab-plugin 6
pipeline-maven 6
repository-connector 6
aws-codecommit-trigger 5
codedx 5
credentials 5
delphix 5
extended-choice-parameter 5
Quick Filters