Known vulnerabilities in Extended Choice Parameter 346.vd87693c5a_86c
Vendor:
Jenkins
Software:
Extended Choice Parameter
Version:
346.vd87693c5a_86c
Software CPE:
cpe:2.3:a:jenkins:extended_choice_parameter:*:*:*:*:*:*:*:*
Website:
https://jenkins.io/
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
7.2
Vulnerabilities by Severity
346.vd87693c5a_86c
-
0.84
0.83
0.82
0.81
0.80
0.79
0.78
0.77
0.76
0.75
0.74
0.73
0.72
0.71
0.70
0.69
0.68
0.67
0.65
0.64
0.63
0.62
0.61
0.60
0.59
0.58
0.56
0.55
0.54
0.53
0.52
0.51
0.50
0.49
0.48
0.47
0.46
0.45
0.44
0.43
0.42
0.41
0.40
0.39
0.38
0.37
0.36
0.35
0.34
0.33
0.32
0.31
0.30
0.29
0.28
0.27
0.26
0.25
0.24
0.23
0.22
0.21
0.20
0.19
0.18
0.17
0.5
0.4
0.3
0.2
0.1
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU62296 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-29038 |
CWE-79 | Low | - | 13.04.2022 |
SB2022041323 |
||
| #VU61414 - Permissions, Privileges, and Access Controls CVE-2022-27205 |
CWE-264 | Medium | - | 16.03.2022 |
SB2022031615 |
||
| #VU61413 - Cross-Site Request Forgery (CSRF) CVE-2022-27204 |
CWE-352 | Low | - | 16.03.2022 |
SB2022031615 |
||
| #VU61412 - Exposure of sensitive information to an unauthorized actor CVE-2022-27203 |
CWE-200 | Medium | - | 16.03.2022 |
SB2022031615 |
||
| #VU61411 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-27202 |
CWE-79 | Low | - | 16.03.2022 |
SB2022031615 |