Known vulnerabilities in Pipeline Utility Steps
Vendor:
Jenkins
Software:
Pipeline Utility Steps
Software CPE:
cpe:2.3:a:jenkins:pipeline_utility_steps:*:*:*:*:*:*:*:*
Website:
https://jenkins.io/
Total vulnerabilities:
3
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.810
2.20.0
2.19.0
2.18.0
2.17.0
2.16.2
2.16.1
2.16.0
2.15.4
2.15.1.1
2.15.3
2.15.2
2.15.1
2.15.0
2.14.0
2.13.2
2.13.1
2.13.0
2.12.2
2.12.1
2.12.0
2.11.0
2.10.0
2.10
2.9.0
2.8.0
2.7.1
2.7.0
2.6.1
2.6.0
2.5.0
2.4.0
2.3.1
2.3.0
2.2.0
2.1.0
2.0.2
2.0.1
2.0
1.5.1
1.5.0
1.4.1
1.4.0
1.3.0
1.2.2
1.2.1
1.2.0
1.1.6
1.1.5
1.1.4
1.1.3
1.1.2
1.1.1
1.1
1.0
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU76236 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2023-32981 |
CWE-22 | Medium | 2.15.3 | 17.05.2023 |
SB2023051751 SB2023061545 SB2023061946 and 1 more |
||
| #VU69367 - Exposure of sensitive information to an unauthorized actor CVE-2022-45381 |
CWE-200 | Medium | 2.13.2 | 16.11.2022 |
SB2022111613 SB2023020889 SB2023022307 and 1 more |
||
| #VU64957 - Improper Control of Generation of Code ('Code Injection') CVE-2022-33980 |
CWE-94 | High | 2.13.1 | 06.07.2022 |
SB2022070645 SB2022072604 SB2022081517 and 31 more |