Lucene search

K

Jenkins Security Vulnerabilities

cve
cve

CVE-2022-30962

Jenkins Global Variable String Parameter Plugin 1.2 and earlier does not escape the name and description of Global Variable String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.4AI Score

0.001EPSS

2022-05-17 03:15 PM
77
2
cve
cve

CVE-2022-30963

Jenkins JDK Parameter Plugin 1.0 and earlier does not escape the name and description of JDK parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.4AI Score

0.001EPSS

2022-05-17 03:15 PM
96
2
cve
cve

CVE-2022-30964

Jenkins Multiselect parameter Plugin 1.3 and earlier does not escape the name and description of Multiselect parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.5AI Score

0.001EPSS

2022-05-17 03:15 PM
79
5
cve
cve

CVE-2022-30965

Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.4AI Score

0.001EPSS

2022-05-17 03:15 PM
74
3
cve
cve

CVE-2022-30966

Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.4AI Score

0.001EPSS

2022-05-17 03:15 PM
92
3
cve
cve

CVE-2022-30967

Jenkins Selection tasks Plugin 1.0 and earlier does not escape the name and description of Script Selection task variable parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.4AI Score

0.001EPSS

2022-05-17 03:15 PM
62
2
cve
cve

CVE-2022-30968

Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.5AI Score

0.001EPSS

2022-05-17 03:15 PM
111
2
cve
cve

CVE-2022-30969

A cross-site request forgery (CSRF) vulnerability in Jenkins Autocomplete Parameter Plugin 1.1 and earlier allows attackers to execute arbitrary code without sandbox protection if the victim is an administrator.

8.8CVSS

9AI Score

0.001EPSS

2022-05-17 03:15 PM
104
3
cve
cve

CVE-2022-30970

Jenkins Autocomplete Parameter Plugin 1.1 and earlier references Dropdown Autocomplete parameter and Auto Complete String parameter names in an unsafe manner from Javascript embedded in view definitions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with It...

5.4CVSS

5.3AI Score

0.001EPSS

2022-05-17 03:15 PM
85
3
cve
cve

CVE-2022-30971

Jenkins Storable Configs Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

8.8CVSS

8.6AI Score

0.001EPSS

2022-05-17 03:15 PM
67
3
cve
cve

CVE-2022-30972

A cross-site request forgery (CSRF) vulnerability in Jenkins Storable Configs Plugin 1.0 and earlier allows attackers to have Jenkins parse a local XML file (e.g., archived artifacts) that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.

8.8CVSS

8.5AI Score

0.001EPSS

2022-05-17 03:15 PM
69
2
cve
cve

CVE-2022-34170

In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does not escape the feature name that is part of its tooltip, effectively undoing the fix for SECURITY-1955, resulting in a cross-site scripting (XSS) vulnerability exploitable by atta...

5.4CVSS

5.3AI Score

0.001EPSS

2022-06-23 05:15 PM
113
4
cve
cve

CVE-2022-34171

In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335) without further esc...

5.4CVSS

5.3AI Score

0.001EPSS

2022-06-23 05:15 PM
102
4
cve
cve

CVE-2022-34172

In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.

5.4CVSS

5.3AI Score

0.001EPSS

2022-06-23 05:15 PM
110
5
cve
cve

CVE-2022-34173

In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
95
4
cve
cve

CVE-2022-34174

In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database security realm.

7.5CVSS

7.4AI Score

0.002EPSS

2022-06-23 05:15 PM
141
4
cve
cve

CVE-2022-34175

Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission checks in the corresponding view.

7.5CVSS

7.2AI Score

0.001EPSS

2022-06-23 05:15 PM
70
4
cve
cve

CVE-2022-34176

Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.

5.4CVSS

5.3AI Score

0.001EPSS

2022-06-23 05:15 PM
211
4
cve
cve

CVE-2022-34177

Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for file parameters for Pipeline input steps on the controller as part of build metadata, using the parameter name without sanitization as a relative path inside a build-related directory, allowing attacker...

7.5CVSS

7.5AI Score

0.001EPSS

2022-06-23 05:15 PM
91
4
cve
cve

CVE-2022-34178

Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability.

6.1CVSS

5.8AI Score

0.001EPSS

2022-06-23 05:15 PM
69
4
cve
cve

CVE-2022-34179

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a style query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerability that allows attackers without Overall/Read permission to sp...

7.5CVSS

7.3AI Score

0.002EPSS

2022-06-23 05:15 PM
58
4
cve
cve

CVE-2022-34180

Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any attacker-specified job...

7.5CVSS

7.3AI Score

0.002EPSS

2022-06-23 05:15 PM
59
4
cve
cve

CVE-2022-34181

Jenkins xUnit Plugin 3.0.8 and earlier implements an agent-to-controller message that creates a user-specified directory if it doesn't exist, and parsing files inside it as test results, allowing attackers able to control agent processes to create an arbitrary directory on the Jenkins controller or...

9.1CVSS

9AI Score

0.002EPSS

2022-06-23 05:15 PM
63
2
cve
cve

CVE-2022-34182

Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflected cross-site scripting (XSS) vulnerability.

6.1CVSS

5.9AI Score

0.001EPSS

2022-06-23 05:15 PM
63
3
cve
cve

CVE-2022-34183

Jenkins Agent Server Parameter Plugin 1.1 and earlier does not escape the name and description of Agent Server parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
65
3
cve
cve

CVE-2022-34184

Jenkins CRX Content Package Deployer Plugin 1.9 and earlier does not escape the name and description of CRX Content Package Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
76
4
cve
cve

CVE-2022-34185

Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
60
4
cve
cve

CVE-2022-34186

Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape the name and description of Moded Extended Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
56
4
cve
cve

CVE-2022-34187

Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objects list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
59
4
cve
cve

CVE-2022-34188

Jenkins Hidden Parameter Plugin 0.0.4 and earlier does not escape the name and description of Hidden Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
63
4
cve
cve

CVE-2022-34189

Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
68
4
cve
cve

CVE-2022-34190

Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.1 and earlier does not escape the name and description of List maven artifact versions parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure ...

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
63
4
cve
cve

CVE-2022-34191

Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
66
4
cve
cve

CVE-2022-34192

Jenkins ontrack Jenkins Plugin 4.0.0 and earlier does not escape the name of Ontrack: Multi Parameter choice, Ontrack: Parameter choice, and Ontrack: SingleParameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers wi...

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
63
4
cve
cve

CVE-2022-34193

Jenkins Package Version Plugin 1.0.1 and earlier does not escape the name of Package version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
65
4
cve
cve

CVE-2022-34194

Jenkins Readonly Parameter Plugin 1.0.0 and earlier does not escape the name and description of Readonly String and Readonly Text parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
70
3
cve
cve

CVE-2022-34195

Jenkins Repository Connector Plugin 2.2.0 and earlier does not escape the name and description of Maven Repository Artifact parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
61
3
cve
cve

CVE-2022-34196

Jenkins REST List Parameter Plugin 1.5.2 and earlier does not escape the name and description of REST list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
60
3
cve
cve

CVE-2022-34197

Jenkins Sauce OnDemand Plugin 1.204 and earlier does not escape the name and description of Sauce Labs Browsers parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
78
3
cve
cve

CVE-2022-34198

Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier does not escape the name and description of Stash Branch parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

5.4CVSS

5.2AI Score

0.001EPSS

2022-06-23 05:15 PM
65
3
cve
cve

CVE-2022-34199

Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

6.5CVSS

6.3AI Score

0.001EPSS

2022-06-23 05:15 PM
65
3
cve
cve

CVE-2022-34200

A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers to connect to an attacker-specified URL.

8.8CVSS

8.6AI Score

0.001EPSS

2022-06-23 05:15 PM
63
3
cve
cve

CVE-2022-34201

A missing permission check in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

6.5CVSS

6.2AI Score

0.001EPSS

2022-06-23 05:15 PM
70
3
cve
cve

CVE-2022-34202

Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

6.5CVSS

6.2AI Score

0.001EPSS

2022-06-23 05:15 PM
69
3
cve
cve

CVE-2022-34203

A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect to an attacker-specified HTTP server.

8.8CVSS

8.6AI Score

0.001EPSS

2022-06-23 05:15 PM
68
2
cve
cve

CVE-2022-34204

A missing permission check in Jenkins EasyQA Plugin 1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server.

4.3CVSS

4.3AI Score

0.001EPSS

2022-06-23 05:15 PM
93
4
cve
cve

CVE-2022-34205

A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests to an attacker-specified URL.

6.5CVSS

6.3AI Score

0.001EPSS

2022-06-23 05:15 PM
77
3
cve
cve

CVE-2022-34206

A missing permission check in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers with Overall/Read permission to send HTTP POST requests to an attacker-specified URL.

4.3CVSS

4.3AI Score

0.001EPSS

2022-06-23 05:15 PM
71
4
cve
cve

CVE-2022-34207

A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specified URL.

6.5CVSS

6.3AI Score

0.001EPSS

2022-06-23 05:15 PM
72
3
cve
cve

CVE-2022-34208

A missing permission check in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

4.3CVSS

4.3AI Score

0.001EPSS

2022-06-23 05:15 PM
80
4
Total number of security vulnerabilities1603