org.jenkins-ci.plugins
1,024 tracked vulnerabilities.
CVE-2022-36894
MEDIUM
Jenkins CLIF Performance Testing Plugin <64 - File Write
Jul 27, 2022
CVSS 6.5
EPSS 0.01
CVE-2022-36893
MEDIUM
Jenkins rpmsign-plugin < 0.5.0 - Missing Authorization in Form Validation
Jul 27, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-36892
MEDIUM
Jenkins rhnpush-plugin < 0.5.1 - Missing Authorization in Form Validation
Jul 27, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-36891
MEDIUM
Jenkins Deployer Framework Plugin < 85.v1d1888e8c021 - Missing Authorization for Deployment Logs
Jul 27, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-36890
MEDIUM
Jenkins Deployer Framework Plugin < 85.v1d1888e8c021 - Path Traversal via Form Validation
Jul 27, 2022
CVSS 4.3
EPSS 0.01
CVE-2022-36889
HIGH
Jenkins Deployer Framework Plugin < 85.v1d1888e8c021 - Arbitrary File Upload via Application Path Configuration
Jul 27, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-36887
MEDIUM
Jenkins Job Configuration History Plugin < 1155.v28a_46a_cc06a_5 - Cross-Site Request Forgery
Jul 27, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-36886
MEDIUM
Jenkins External Monitor Job Type Plugin < 191.v363d0d1efdf8 - Cross-Site Request Forgery
Jul 27, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-36884
MEDIUM
Jenkins Git Plugin < 4.11.3 - Unauthenticated Information Disclosure via Webhook Endpoint
Jul 27, 2022
CVSS 5.3
EPSS 0.01
CVE-2022-36883
HIGH
NUCLEI
Jenkins Git Plugin < 4.11.3 - Unauthenticated Build Trigger and Arbitrary Repository Checkout
Jul 27, 2022
CVSS 7.5
EPSS 0.81
CVE-2022-36882
HIGH
Jenkins Git Plugin < 4.11.3 - Cross-Site Request Forgery
Jul 27, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-36881
HIGH
Jenkins Git client Plugin <= 3.11.0 - SSH Host Key Verification Bypass
Jul 27, 2022
CVSS 8.1
EPSS 0.01
CVE-2022-34816
MEDIUM
Jenkins HPE Network Virtualization Plugin 1.0 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34815
MEDIUM
Jenkins Request Rename Or Delete Plugin < 1.1.0 - Cross-Site Request Forgery
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34814
MEDIUM
Jenkins Request Rename Or Delete Plugin < 1.1.0 - Unauthorized Access to Administrative Configuration Page
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34813
MEDIUM
Jenkins XPath Configuration Viewer Plugin < 1.1.1 - Missing Authorization for XPath Expression Management
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34812
MEDIUM
Jenkins XPath Configuration Viewer Plugin < 1.1.1 - Cross-Site Request Forgery
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34811
MEDIUM
Jenkins XPath Configuration Viewer Plugin < 1.1.1 - Missing Authorization
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34808
MEDIUM
Jenkins Cisco Spark Plugin < 1.1.1 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34807
MEDIUM
Jenkins Elasticsearch Query Plugin <= 1.2 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34806
MEDIUM
Jenkins Jigomerge < 0.9 - Insufficiently Protected Credentials in Job Config Files
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34805
MEDIUM
Jenkins Skype notifier Plugin < 1.1.0 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-34804
MEDIUM
Jenkins OpsGenie Plugin < 1.9 - Cleartext Transmission of Sensitive Information via Configuration Forms
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34803
MEDIUM
Jenkins OpsGenie Plugin < 1.9 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-34802
MEDIUM
Jenkins RocketChat Notifier Plugin <= 1.5.2 - Insufficiently Protected Credentials
Jun 30, 2022
CVSS 4.3
EPSS 0.00
Products
script-security 35
git 13
email-ext 11
active-directory 9
config-file-provider 9
electricflow 9
ec2 8
oic-auth 8
subversion 8
artifactory 7
credentials-binding 7
htmlpublisher 7
jobConfigHistory 7
mercurial 7
openshift-deployer 7
rundeck 7
azure-ad 6
azure-vm-agents 6
ec2-deployment-dashboard 6
fortify-on-demand-uploader 6
ghprb 6
gitlab-oauth 6
gitlab-plugin 6
pipeline-maven 6
repository-connector 6
aws-codecommit-trigger 5
codedx 5
credentials 5
delphix 5
extended-choice-parameter 5
Quick Filters