Known vulnerabilities in Config File Provider
Vendor:
Jenkins
Software:
Config File Provider
Software CPE:
cpe:2.3:a:jenkins:config_file_provider:*:*:*:*:*:*:*:*
Website:
https://jenkins.io/
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
7.2
Breakdown by Severity Chart
1013
1006
1002
994
988
982
980
978
973
968
959
953.v0432a_802e4d2
952.va_544a_6234b_46
953
951.953
952
951
938
3.11.1
3.11.0
3.11
3.10.0
3.9.0
3.8.2
3.8.1
3.7.2
3.8.0
3.7.1
3.7.0
3.6.3
3.6.2
3.6.1
3.6
3.5
3.4.1
3.4
3.3
3.2
3.1
3.0
2.18
2.17
2.16.4
2.16.3
2.16.2
2.16.1
2.16.0
2.15.7
2.15.6
2.15.5
2.15.4
2.15.3
2.15.2
2.15.1
2.15
2.14.2
2.14.1
2.14
2.13
2.12
2.11
2.10.1
2.10.0
2.9.3
2.9.2
2.9.1
2.8.1
2.7.5
2.7.4
2.7.3
2.7.2
2.7.1
2.7
2.6.2
2.6.1
2.6
2.5.1
2.5
2.4
2.3
2.2.1
2.1.1
2.1
2.0
1.9.1
1.6.1
1.6
1.5
1.4
1.3.4
1.3.3
1.3.2
1.3.1
1.3
1.2
1.1
1.0
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU79888 - Exposure of sensitive information to an unauthorized actor CVE-2023-40339 |
CWE-200 | Low | 953.v0432a_802e4d2 | 23.08.2023 |
SB2023082323 SB2023112014 SB2024021216 and 1 more |
||
| #VU52495 - Permissions, Privileges, and Access Controls CVE-2021-21645 |
CWE-264 | Low | 3.7.1 | 22.04.2021 |
SB2021042205 SB2021060101 SB2021063033 and 3 more |
||
| #VU52494 - Cross-Site Request Forgery (CSRF) CVE-2021-21644 |
CWE-352 | Low | 3.7.1 | 22.04.2021 |
SB2021042205 SB2021060101 SB2021063033 and 3 more |
||
| #VU52493 - Permissions, Privileges, and Access Controls CVE-2021-21643 |
CWE-264 | Low | 3.7.1 | 22.04.2021 |
SB2021042205 SB2021060101 SB2021063033 and 3 more |
||
| #VU52492 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2021-21642 |
CWE-611 | Medium | 3.7.1 | 22.04.2021 |
SB2021042205 SB2021060101 SB2021063033 and 3 more |