Known vulnerabilities in jenkins-2-plugins (Red Hat package) - page 10

Software CPE: cpe:2.3:o:red_hat:jenkins-2-plugins_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 232
Public exploits: 16
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting jenkins-2-plugins (Red Hat package) jenkins-2-plugins (Red Hat package) is affected by 232 known vulnerabilities: 30 high, 125 medium, 77 low Critical High Medium Low

Vulnerabilities (232)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU52902 - Improper Validation of Array Index
CVE-2021-3121
CWE-129 High
No
No
4.7.1616671397-1.el8, 4.8.1624022417-1.el8 06.05.2021 SB2021011120
SB2021050602
SB2021050603
and 34 more
#VU52495 - Permissions, Privileges, and Access Controls
CVE-2021-21645
CWE-264 Low
No
No
3.11.1624366838-1.el7, 4.5.1623326336-1.el7, 4.6.1623162648-1.el8, 4.7.1621361158-1.el8 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52494 - Cross-Site Request Forgery (CSRF)
CVE-2021-21644
CWE-352 Low
No
No
3.11.1624366838-1.el7, 4.5.1623326336-1.el7, 4.6.1623162648-1.el8, 4.7.1621361158-1.el8 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52493 - Permissions, Privileges, and Access Controls
CVE-2021-21643
CWE-264 Low
No
No
3.11.1624366838-1.el7, 4.5.1623326336-1.el7, 4.6.1623162648-1.el8, 4.7.1621361158-1.el8 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52492 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2021-21642
CWE-611 Medium
No
No
3.11.1624366838-1.el7, 4.5.1623326336-1.el7, 4.6.1623162648-1.el8, 4.7.1621361158-1.el8 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52385 - Improper input validation
CVE-2020-27223
CWE-20 Medium
Available
No
3.11.1624366838-1.el7, 4.5.1623326336-1.el7 21.04.2021 SB2021042107
SB2021063002
SB2021063034
and 19 more
#VU49525 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21611
CWE-79 Low
No
No
4.6.1612257979-1.el8 14.01.2021 SB2021011418
SB2021011453
SB2021012106
and 2 more
#VU49524 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21610
CWE-79 Low
No
No
4.6.1612257979-1.el8 14.01.2021 SB2021011418
SB2021011452
SB2021012106
and 2 more
#VU49523 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21608
CWE-79 Low
No
No
4.6.1612257979-1.el8 14.01.2021 SB2021011418
SB2021011450
SB2021012106
and 2 more
#VU49522 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21603
CWE-79 Low
No
No
4.6.1612257979-1.el8 13.01.2021 SB2021011418
SB2021011445
SB2021012106
and 2 more
#VU49526 - XML Injection
CVE-2021-21604
CWE-91 Medium
No
No
4.6.1612257979-1.el8 13.01.2021 SB2021011418
SB2021011446
SB2021012106
and 2 more
#VU49527 - Exposure of sensitive information to an unauthorized actor
CVE-2021-21602
CWE-200 Medium
No
No
4.6.1612257979-1.el8 13.01.2021 SB2021011418
SB2021011444
SB2021012106
and 2 more
#VU49528 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-21605
CWE-22 Medium
No
No
4.6.1612257979-1.el8 13.01.2021 SB2021011418
SB2021011447
SB2021012106
and 2 more
#VU49529 - Permissions, Privileges, and Access Controls
CVE-2021-21606
CWE-264 Low
No
No
4.6.1612257979-1.el8 13.01.2021 SB2021011418
SB2021011448
SB2021012106
and 2 more
#VU49530 - Memory corruption
CVE-2021-21607
CWE-119 Medium
No
No
4.6.1612257979-1.el8 13.01.2021 SB2021011418
SB2021011449
SB2021012106
and 2 more
#VU49531 - Permissions, Privileges, and Access Controls
CVE-2021-21609
CWE-264 Low
No
No
4.6.1612257979-1.el8 13.01.2021 SB2021011418
SB2021011451
SB2021012106
and 2 more
#VU45699 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-16845
CWE-835 Medium
No
No
4.7.1621361158-1.el8 14.08.2020 SB2020081403
SB2020081404
SB2020081405
and 44 more
#VU31891 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-15586
CWE-362 Medium
No
No
4.7.1621361158-1.el8 27.07.2020 SB2020072734
SB2020072735
SB2020072749
and 37 more
#VU27924 - Incorrect Default Permissions
CVE-2020-1945
CWE-276 Low
No
No
4.6.1612257979-1.el8 15.05.2020 SB2020051501
SB2020052114
SB2020060205
and 48 more
#VU47428 - Permissions, Privileges, and Access Controls
CVE-2020-11979
CWE-264 Low
No
No
4.6.1612257979-1.el8 14.05.2020 SB2020100804
SB2020100815
SB2020111614
and 51 more


Showing elements 181 - 200 out of 232