org.jenkins-ci.plugins

1,024 tracked vulnerabilities.

CVE-2022-23112 MEDIUM
Jenkins Publish Over SSH Plugin < 1.22 - Missing Authorization for SSH Server Connection
Jan 12, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-23111 MEDIUM
Jenkins Publish Over SSH Plugin < 1.22 - Cross-Site Request Forgery
Jan 12, 2022
CVSS 4.3
EPSS 0.01
CVE-2022-23110 MEDIUM
Jenkins Publish Over SSH Plugin <= 1.22 - Stored Cross-Site Scripting via SSH Server Name
Jan 12, 2022
CVSS 4.8
EPSS 0.00
CVE-2022-23108 MEDIUM
Jenkins Badge Plugin < 1.9 - Stored Cross-Site Scripting via Badge Description
Jan 12, 2022
CVSS 5.4
EPSS 0.00
CVE-2022-23105 MEDIUM
Jenkins Active Directory Plugin < 2.25 - Cleartext Transmission of Sensitive Information
Jan 12, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-20621 MEDIUM
Jenkins Metrics Plugin <4.0.2.8 - Info Disclosure
Jan 12, 2022
CVSS 5.5
EPSS 0.00
CVE-2022-20620 MEDIUM
Jenkins SSH Agent Plugin <1.23 - Info Disclosure
Jan 12, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-20619 HIGH
Jenkins Bitbucket Branch Source Plugin <737.vdf9dc06105be - CSRF
Jan 12, 2022
CVSS 7.1
EPSS 0.00
CVE-2022-20618 MEDIUM
Jenkins Bitbucket Branch Source Plugin < 737.vdf9dc06105be - Missing Authorization for Credential ID Enumeration
Jan 12, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-20617 HIGH
Jenkins Docker Commons Plugin <1.17 - Command Injection
Jan 12, 2022
CVSS 8.8
EPSS 0.01
CVE-2022-20616 MEDIUM
Jenkins Credentials Binding Plugin <1.27 - Privilege Escalation
Jan 12, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-20615 MEDIUM
Jenkins Matrix Project Plugin <1.19 - XSS
Jan 12, 2022
CVSS 5.4
EPSS 0.03
CVE-2022-20614 MEDIUM
Jenkins Mailer Plugin <391.ve4a_38c1f - Info Disclosure
Jan 12, 2022
CVSS 4.3
EPSS 0.00
CVE-2022-20613 MEDIUM
Jenkins Mailer Plugin <391.ve4a_38c1b_cf4b - CSRF
Jan 12, 2022
CVSS 4.3
EPSS 0.00
CVE-2021-43578 HIGH
Jenkins Squash TM Publisher <1.0.0 - Code Injection
Nov 12, 2021
CVSS 8.1
EPSS 0.00
CVE-2021-43577 HIGH
Jenkins OWASP Dependency-Check Plugin <5.1.1 - XXE
Nov 12, 2021
CVSS 7.1
EPSS 0.00
CVE-2021-43576 MEDIUM
Jenkins pom2config Plugin <1.2 - XXE
Nov 12, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-21701 MEDIUM
Jenkins Performance Plugin < 3.20 - XML External Entity Injection
Nov 12, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-21700 MEDIUM
Jenkins Scriptler Plugin < 3.3 - Stored Cross-Site Scripting in Script Deletion Confirmation
Nov 12, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-21698 HIGH
Jenkins Subversion Plugin < 2.15.0 - Path Traversal via Subversion Key File Lookup
Nov 04, 2021
CVSS 7.5
EPSS 0.04
CVE-2021-21684 MEDIUM
Jenkins Git Plugin < 4.8.2 - Stored Cross-Site Scripting via Git SHA-1 Checksum Parameter
Oct 06, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-21681 MEDIUM
Jenkins Nomad Plugin < 0.7.4 - Insufficiently Protected Docker Credentials
Aug 31, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-21680 HIGH
Jenkins Nested View Plugin < 1.20 - XML External Entity Injection
Aug 31, 2021
CVSS 7.1
EPSS 0.00
CVE-2021-21679 HIGH
Jenkins Azure AD Plugin < 179.vf6841393099e - Cross-Site Request Forgery Protection Bypass
Aug 31, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-21678 HIGH
Jenkins SAML Plugin < 2.0.7 - Cross-Site Request Forgery Protection Bypass
Aug 31, 2021
CVSS 8.8
EPSS 0.00