org.jenkins-ci.plugins

1,024 tracked vulnerabilities.

CVE-2024-2215 MEDIUM
Jenkins docker-build-step Plugin <2.11 - CSRF
Mar 06, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-28162 MEDIUM
Jenkins Delphix Plugin 3.0.1-3.1.0 - Improper Certificate Validation in Data Control Tower Connections
Mar 06, 2024
CVSS 4.2
EPSS 0.00
CVE-2024-28161 MEDIUM
Jenkins Delphix Plugin 3.0.1 - Improper Certificate Validation
Mar 06, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-28160 HIGH
Jenkins iceScrum Plugin < 1.1.6 - Stored Cross-Site Scripting via Project URL
Mar 06, 2024
CVSS 8.8
EPSS 0.01
CVE-2024-28159 MEDIUM
Jenkins Subversion Partial Release Manager Plugin <= 1.0.1 - Missing Authorization
Mar 06, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-28158 MEDIUM
Jenkins Subversion Partial Release Manager Plugin < 1.0.1 - Cross-Site Request Forgery
Mar 06, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-28157 HIGH
Jenkins GitBucket Plugin <= 0.8 - Stored Cross-Site Scripting in Build Views
Mar 06, 2024
CVSS 8.0
EPSS 0.04
CVE-2024-28156 MEDIUM
Jenkins Build Monitor View Plugin < 1.14-860.vd06ef2568b_3f - Stored Cross-Site Scripting via Unescaped View Names
Mar 06, 2024
CVSS 5.4
EPSS 0.39
CVE-2024-28153 MEDIUM
Jenkins OWASP Dependency-Check Plugin < 5.4.6 - Stored Cross-Site Scripting via Unescaped Vulnerability Metadata
Mar 06, 2024
CVSS 5.4
EPSS 0.01
CVE-2024-28152 MEDIUM
Jenkins Bitbucket Branch Source Plugin <866.vdea_7dcd3008e - Info D...
Mar 06, 2024
CVSS 6.3
EPSS 0.00
CVE-2024-28151 MEDIUM
Jenkins HTML Publisher Plugin <= 1.32 - Path Traversal via Symbolic Link Handling
Mar 06, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-28150 MEDIUM
Jenkins HTML Publisher Plugin < 1.32.1 - Stored Cross-Site Scripting via Job Names and Report Titles
Mar 06, 2024
CVSS 4.7
EPSS 0.00
CVE-2024-28149 MEDIUM
Jenkins HTML Publisher Plugin 1.16-1.32 - Cross-Site Scripting via Improper Input Sanitization
Mar 06, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-23904 HIGH
Jenkins Log Command Plugin < 1.0.2 - Unauthenticated Arbitrary File Read via Command Parser
Jan 24, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-23900 MEDIUM
Jenkins Matrix Project Plugin <822.v01b_8c85d16d2 - Privilege Escal...
Jan 24, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-23899 MEDIUM
Jenkins Git Server Plugin < 99.va_0826a_b_cdfa_d - Arbitrary File Read via Command Parser
Jan 24, 2024
CVSS 6.5
EPSS 0.00
CVE-2023-50775 MEDIUM
Jenkins Deployment Dashboard Plugin < 1.0.10 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50774 HIGH
Jenkins HTMLResource Plugin 1.02 - Cross-Site Request Forgery
Dec 13, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-50771 MEDIUM
Jenkins OpenId Connect Authentication Plugin < 2.6 - Open Redirect via Login Redirect URL
Dec 13, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-50770 MEDIUM
Jenkins OpenId Connect Authentication Plugin < 2.6 - Insufficiently Protected Credentials
Dec 13, 2023
CVSS 6.7
EPSS 0.00
CVE-2023-50765 MEDIUM
Jenkins Scriptler Plugin < 342.v6a_89fd40f466 - Unauthorized Groovy Script Content Read via Script ID
Dec 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-50764 HIGH
Jenkins Scriptler Plugin <342.v6a_89fd40f466 - File Deletion
Dec 13, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-49656 CRITICAL
Jenkins MATLAB Plugin < 2.11.1 - XML External Entity Injection
Nov 29, 2023
CVSS 9.8
EPSS 0.00
CVE-2023-49655 HIGH
Jenkins MATLAB Plugin < 2.11.1 - Cross-Site Request Forgery
Nov 29, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-49654 CRITICAL
Jenkins MATLAB Plugin < 2.11.1 - Unauthenticated XML File Parsing via Missing Permission Checks
Nov 29, 2023
CVSS 9.8
EPSS 0.00