Known vulnerabilities in JIRA plugin
Vendor:
Jenkins
Software:
JIRA plugin
Software CPE:
cpe:2.3:a:jenkins:jira_plugin:*:*:*:*:*:*:*:*
Website:
https://jenkins.io/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
7.2
Breakdown by Severity Chart
3.21
3.20
3.19
3.18
3.17
3.16
3.15
1.17.1
3.14
1.17.0
3.13
1.15.1
3.12
3.11
3.10
3.9
1.13.3
3.8
1.13.0
3.1
3.7.1
3.6.1
3.7
2.7.0
1.12.2
3.6
2.24
2.12.4
2.6.5
3.5
3.4
2.41
2.6.4
1.11.5
3.3
3.2.1
3.2
3.1.3
3.1.2
3.1.1
3.1.0
3.0.18
3.0.17
3.0.16
3.0.15
3.0.14
3.0.13
3.0.12
3.0.6.1
2.40
2.38
2.23
2.22
2.12.3
2.12.1
2.11.3
2.11.0
2.10.2
2.8.11.2
2.6.1
2.6.0
2.5.5
2.5
2.3.14
2.3.13
2.1.19
2.1.14
2.0.0
1.533
1.532
1.480
1.424
1.405
1.403
1.397
1.393
1.36
1.32.1
1.16
1.14
1.11.4
1.11.3
1.11.2
1.11.1
1.3.9
1.3.8
1.3
1.0
3.0.11
3.0.10
3.0.9
3.0.8
3.0.7
3.0.6
3.0.5
3.0.4
3.0.3
3.0.2
3.0.1
3.0.0
2.5.2
2.4.2
2.4
2.3.1
2.3
2.2.1
2.2
2.1
2.0.3
2.0.2
2.0.1
2.0
1.41
1.39
1.38
1.37
1.35
1.34
1.33
1.32
1.31
1.30
1.29
1.28
1.27
1.26
1.25
1.24
1.23
1.22
1.21
1.20
1.19
1.18
1.17
1.15
1.13
1.12
1.11
1.10
1.9
1.8
1.7
1.6
1.5
1.4
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU83586 - Exposure of sensitive information to an unauthorized actor CVE-2023-49653 |
CWE-200 | Low | 3.12 | 30.11.2023 |
SB2023113008 |
||
| #VU62299 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2022-29041 |
CWE-79 | Low | 3.6.1, 3.7.1 | 13.04.2022 |
SB2022041328 SB2022051924 |
||
| #VU22919 - Exposure of sensitive information to an unauthorized actor CVE-2019-16541 |
CWE-200 | Medium | 3.0.11 | 22.11.2019 |
SB2019112207 |