Known vulnerabilities in Pipeline: Input Step
Vendor:
Jenkins
Software:
Pipeline: Input Step
Software CPE:
cpe:2.3:a:jenkins:pipeline_input_step:*:*:*:*:*:*:*:*
Website:
https://jenkins.io/
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU68600 - Cross-Site Request Forgery (CSRF) CVE-2022-43407 |
CWE-352 | Low | 456.vd8a_957db_5b_e9 | 24.10.2022 |
SB2022102419 SB2023020889 SB2023022307 and 4 more |
||
| #VU64608 - Improper input validation CVE-2022-34177 |
CWE-20 | Medium | 449.v77f0e8b_845c4 | 23.06.2022 |
SB2022062315 SB2022092149 SB2023010903 and 2 more |