org.jenkins-ci.plugins
1,024 tracked vulnerabilities.
CVE-2022-23112
MEDIUM
Jenkins Publish Over SSH Plugin < 1.22 - Missing Authorization for SSH Server Connection
Jan 12, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-23111
MEDIUM
Jenkins Publish Over SSH Plugin < 1.22 - Cross-Site Request Forgery
Jan 12, 2022
CVSS 4.3
EPSS 0.01
CVE-2022-23110
MEDIUM
Jenkins Publish Over SSH Plugin <= 1.22 - Stored Cross-Site Scripting via SSH Server Name
Jan 12, 2022
CVSS 4.8
EPSS 0.00
CVE-2022-23108
MEDIUM
Jenkins Badge Plugin < 1.9 - Stored Cross-Site Scripting via Badge Description
Jan 12, 2022
CVSS 5.4
EPSS 0.00
CVE-2022-23105
MEDIUM
Jenkins Active Directory Plugin < 2.25 - Cleartext Transmission of Sensitive Information
Jan 12, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-20621
MEDIUM
Jenkins Metrics Plugin <4.0.2.8 - Info Disclosure
Jan 12, 2022
CVSS 5.5
EPSS 0.00
CVE-2022-20620
MEDIUM
Jenkins SSH Agent Plugin <1.23 - Info Disclosure
Jan 12, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-20619
HIGH
Jenkins Bitbucket Branch Source Plugin <737.vdf9dc06105be - CSRF
Jan 12, 2022
CVSS 7.1
EPSS 0.00
CVE-2022-20618
MEDIUM
Jenkins Bitbucket Branch Source Plugin < 737.vdf9dc06105be - Missing Authorization for Credential ID Enumeration
Jan 12, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-20617
HIGH
Jenkins Docker Commons Plugin <1.17 - Command Injection
Jan 12, 2022
CVSS 8.8
EPSS 0.01
CVE-2022-20616
MEDIUM
Jenkins Credentials Binding Plugin <1.27 - Privilege Escalation
Jan 12, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-20615
MEDIUM
Jenkins Matrix Project Plugin <1.19 - XSS
Jan 12, 2022
CVSS 5.4
EPSS 0.03
CVE-2022-20614
MEDIUM
Jenkins Mailer Plugin <391.ve4a_38c1f - Info Disclosure
Jan 12, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-20613
MEDIUM
Jenkins Mailer Plugin <391.ve4a_38c1b_cf4b - CSRF
Jan 12, 2022
CVSS 4.3
EPSS 0.00
CVE-2021-43578
HIGH
Jenkins Squash TM Publisher <1.0.0 - Code Injection
Nov 12, 2021
CVSS 8.1
EPSS 0.00
CVE-2021-43577
HIGH
Jenkins OWASP Dependency-Check Plugin <5.1.1 - XXE
Nov 12, 2021
CVSS 7.1
EPSS 0.00
CVE-2021-43576
MEDIUM
Jenkins pom2config Plugin <1.2 - XXE
Nov 12, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-21701
MEDIUM
Jenkins Performance Plugin < 3.20 - XML External Entity Injection
Nov 12, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-21700
MEDIUM
Jenkins Scriptler Plugin < 3.3 - Stored Cross-Site Scripting in Script Deletion Confirmation
Nov 12, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-21698
HIGH
Jenkins Subversion Plugin < 2.15.0 - Path Traversal via Subversion Key File Lookup
Nov 04, 2021
CVSS 7.5
EPSS 0.04
CVE-2021-21684
MEDIUM
Jenkins Git Plugin < 4.8.2 - Stored Cross-Site Scripting via Git SHA-1 Checksum Parameter
Oct 06, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-21681
MEDIUM
Jenkins Nomad Plugin < 0.7.4 - Insufficiently Protected Docker Credentials
Aug 31, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-21680
HIGH
Jenkins Nested View Plugin < 1.20 - XML External Entity Injection
Aug 31, 2021
CVSS 7.1
EPSS 0.00
CVE-2021-21679
HIGH
Jenkins Azure AD Plugin < 179.vf6841393099e - Cross-Site Request Forgery Protection Bypass
Aug 31, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-21678
HIGH
Jenkins SAML Plugin < 2.0.7 - Cross-Site Request Forgery Protection Bypass
Aug 31, 2021
CVSS 8.8
EPSS 0.00
Products
script-security 35
git 13
email-ext 11
active-directory 9
config-file-provider 9
electricflow 9
ec2 8
oic-auth 8
subversion 8
artifactory 7
credentials-binding 7
htmlpublisher 7
jobConfigHistory 7
mercurial 7
openshift-deployer 7
rundeck 7
azure-ad 6
azure-vm-agents 6
ec2-deployment-dashboard 6
fortify-on-demand-uploader 6
ghprb 6
gitlab-oauth 6
gitlab-plugin 6
pipeline-maven 6
repository-connector 6
aws-codecommit-trigger 5
codedx 5
credentials 5
delphix 5
extended-choice-parameter 5
Quick Filters