org.jenkins-ci.plugins
1,024 tracked vulnerabilities.
CVE-2023-49653
MEDIUM
Jenkins Jira Plugin < 3.11 - Insufficiently Protected Credentials
Nov 29, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-49652
LOW
Jenkins Google Compute Engine Plugin < 4.3.17.1 - Missing Authorization for Credential Enumeration
Nov 29, 2023
CVSS 2.7
EPSS 0.00
CVE-2023-46660
MEDIUM
Jenkins Zanata Plugin <0.6 - Info Disclosure
Oct 25, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-46659
MEDIUM
Jenkins Edgewall Trac Plugin <1.13 - XSS
Oct 25, 2023
CVSS 5.4
EPSS 0.01
CVE-2023-46657
MEDIUM
Jenkins Gogs Plugin <1.0.15 - Info Disclosure
Oct 25, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-46655
MEDIUM
Jenkins CloudBees CD Plugin <1.1.32 - Path Traversal
Oct 25, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-46654
HIGH
Jenkins CloudBees CD Plugin <1.1.32 - Privilege Escalation
Oct 25, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-46653
MEDIUM
Jenkins lambdatest-automation <1.20.10 - Info Disclosure
Oct 25, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-46652
MEDIUM
Jenkins lambdatest-automation <1.20.9 - Info Disclosure
Oct 25, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-41945
HIGH
Jenkins Assembla Auth Plugin < 1.14 - Missing Authorization
Sep 06, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-41944
MEDIUM
Jenkins AWS CodeCommit Trigger Plugin <= 3.0.12 - HTML Injection via Queue Name Parameter
Sep 06, 2023
CVSS 6.1
EPSS 0.00
CVE-2023-41943
MEDIUM
Jenkins AWS CodeCommit Trigger Plugin < 3.0.12 - Missing Authorization in HTTP Endpoint
Sep 06, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-41942
MEDIUM
Jenkins AWS CodeCommit Trigger Plugin < 3.0.12 - Cross-Site Request Forgery
Sep 06, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-41941
MEDIUM
Jenkins AWS CodeCommit Trigger Plugin < 3.0.12 - Missing Authorization for Credential ID Enumeration
Sep 06, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-41939
HIGH
Jenkins SSH2 Easy Plugin <1.4 - Privilege Escalation
Sep 06, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-41938
MEDIUM
Jenkins Ivy Plugin < 2.5 - Cross-Site Request Forgery
Sep 06, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-41936
HIGH
Jenkins Google Login Plugin <1.7 - Info Disclosure
Sep 06, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-41935
HIGH
Jenkins Azure AD Plugin < 396.v86ce29279947 - Non-Constant Time Comparison in CSRF Nonce Check
Sep 06, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-41934
MEDIUM
Jenkins Pipeline Maven Integration Plugin < 1330.v18e473854496 - Sensitive Information Exposure in Build Logs
Sep 06, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-41933
HIGH
Jenkins Job Configuration History Plugin < 1229.v3039470161a_d - XML External Entity Injection
Sep 06, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-41932
MEDIUM
Jenkins Job Configuration History Plugin < 1227.v7a_79fc4dc01f - Directory Deletion via Timestamp Query Parameter
Sep 06, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-41931
MEDIUM
Jenkins Job Configuration History Plugin < 1227.v7a_79fc4dc01f - Stored Cross-Site Scripting in History View Timestamp
Sep 06, 2023
CVSS 5.4
EPSS 0.01
CVE-2023-41930
MEDIUM
Jenkins Job Configuration History Plugin < 1227.v7a_79fc4dc01f - Path Traversal via Name Query Parameter
Sep 06, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-4303
MEDIUM
Jenkins Fortify Plugin <22.1.38 - XSS
Aug 21, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-4302
MEDIUM
Jenkins Fortify Plugin <22.1.38 - Open Redirect
Aug 21, 2023
CVSS 4.2
EPSS 0.00
Products
script-security 35
git 13
email-ext 11
active-directory 9
config-file-provider 9
electricflow 9
ec2 8
oic-auth 8
subversion 8
artifactory 7
credentials-binding 7
htmlpublisher 7
jobConfigHistory 7
mercurial 7
openshift-deployer 7
rundeck 7
azure-ad 6
azure-vm-agents 6
ec2-deployment-dashboard 6
fortify-on-demand-uploader 6
ghprb 6
gitlab-oauth 6
gitlab-plugin 6
pipeline-maven 6
repository-connector 6
aws-codecommit-trigger 5
codedx 5
credentials 5
delphix 5
extended-choice-parameter 5
Quick Filters