Known vulnerabilities in jenkins-2-plugins (Red Hat package) - page 2

Software CPE: cpe:2.3:o:red_hat:jenkins-2-plugins_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 232
Public exploits: 16
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting jenkins-2-plugins (Red Hat package) jenkins-2-plugins (Red Hat package) is affected by 232 known vulnerabilities: 30 high, 125 medium, 77 low Critical High Medium Low

Vulnerabilities (232)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU85790 - Missing Origin Validation in WebSockets
CVE-2024-23898
CWE-1385 High
Available
No
4.11.1706516946-1.el8, 4.12.1706515741-1.el8, 4.13.1706516346-1.el8 25.01.2024 SB2024012513
SB2024021214
SB2024021215
and 1 more
#VU85786 - Improper Access Control
CVE-2024-23897
CWE-284 High
Available
Exploited
4.11.1706516946-1.el8, 4.12.1706515741-1.el8, 4.13.1706516346-1.el8 25.01.2024 SB2024012513
SB2024021214
SB2024021215
and 6 more
#VU80791 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-40167
CWE-444 Medium
No
No
4.12.1706515741-1.el8 14.09.2023 SB2023091440
SB2023092933
SB2023101760
and 68 more
#VU79888 - Exposure of sensitive information to an unauthorized actor
CVE-2023-40339
CWE-200 Low
No
No
4.12.1706515741-1.el8, 4.14.1706516441-1.el8 23.08.2023 SB2023082323
SB2023112014
SB2024021216
and 1 more
#VU79886 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-40338
CWE-22 Low
No
No
4.12.1706515741-1.el8, 4.14.1706516441-1.el8 23.08.2023 SB2023082322
SB2023112014
SB2024021216
and 1 more
#VU79885 - Cross-Site Request Forgery (CSRF)
CVE-2023-40337
CWE-352 Low
No
No
4.12.1706515741-1.el8, 4.14.1706516441-1.el8 23.08.2023 SB2023082322
SB2023112014
SB2024021216
and 1 more
#VU78258 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-37947
CWE-601 Low
No
No
4.12.1706515741-1.el8, 4.14.1706516441-1.el8 14.07.2023 SB2023071418
SB2024021216
SB2024021217
#VU77107 - Incorrect Default Permissions
CVE-2023-2976
CWE-276 Low
No
No
4.12.1706515741-1.el8, 4.14.1706516441-1.el8 08.06.2023 SB2023060849
SB2023071712
SB2023072512
and 157 more
#VU75562 - Improper input validation
CVE-2023-20861
CWE-20 Medium
No
No
4.12.1686649756-1.el8, 4.12.1706515741-1.el8, 4.13.1686680473-1.el8 27.04.2023 SB2023042742
SB2023042746
SB2023042832
and 61 more
#VU75408 - Security Features
CVE-2023-20862
CWE-254 Medium
No
No
4.12.1706515741-1.el8 21.04.2023 SB2023042130
SB2023042132
SB2023053121
and 20 more
#VU75218 - Resource exhaustion
CVE-2023-26048
CWE-400 Medium
No
No
4.12.1706515741-1.el8 18.04.2023 SB2023041842
SB2023051753
SB2023060701
and 55 more
#VU75217 - Improper input validation
CVE-2023-26049
CWE-20 Low
No
No
4.12.1706515741-1.el8 18.04.2023 SB2023041842
SB2023051821
SB2023060836
and 78 more
#VU72438 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-25762
CWE-79 Low
No
No
4.10.1681719745-1.el8, 4.11.1683009941-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8, 4.12.1683009955-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1684911916-1.el8, 4.13.1698292274-1.el8, 4.13.1706516346-1.el8, 4.14.1706516441-1.el8 21.02.2023 SB2023022118
SB2023042646
SB2023051806
and 9 more
#VU72437 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-25761
CWE-79 Low
No
No
4.10.1681719745-1.el8, 4.11.1683009941-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8, 4.12.1683009955-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1684911916-1.el8, 4.13.1698292274-1.el8, 4.13.1706516346-1.el8, 4.14.1706516441-1.el8 21.02.2023 SB2023022116
SB2023042646
SB2023051806
and 9 more
#VU72076 - Incorrect Authorization
CVE-2020-7692
CWE-863 High
No
No
4.9.1675668922-1.el8, 4.10.1675144701-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1684911916-1.el8 08.02.2023 SB2020070955
SB2023020889
SB2023022307
and 9 more
#VU71499 - Permissions, Privileges, and Access Controls
CVE-2023-24422
CWE-264 Medium
No
No
4.10.1680703106-1.el8, 4.11.1683009941-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8, 4.12.1683009955-1.el8, 4.12.1686649756-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1684911916-1.el8, 4.13.1698292274-1.el8, 4.13.1706516346-1.el8, 4.14.1706516441-1.el8 25.01.2023 SB2023012504
SB2023041270
SB2023041272
and 14 more
#VU67665 - Resource exhaustion
CVE-2022-25857
CWE-400 Medium
No
No
4.9.1675668922-1.el8, 4.10.1675144701-1.el8, 4.11.1683009941-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1698292274-1.el8, 4.13.1706516346-1.el8, 4.14.1706516441-1.el8 27.09.2022 SB2022092714
SB2022092728
SB2022100555
and 83 more
#VU66065 - Resource exhaustion
CVE-2022-1962
CWE-400 Medium
No
No
4.12.1706515741-1.el8 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 73 more
#VU62608 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-29599
CWE-78 High
No
No
4.9.1674644684-1.el8, 4.10.1670851835-1.el8, 4.11.1683009941-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8, 4.12.1686649756-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1686680473-1.el8, 4.13.1698292274-1.el8, 4.13.1706516346-1.el8, 4.14.1706516441-1.el8 26.04.2022 SB2022042627
SB2022042724
SB2022050234
and 29 more
#VU62492 - Origin Validation Error
CVE-2021-26291
CWE-346 High
No
No
4.11.1683009941-1.el8, 4.12.1706515741-1.el8, 4.13.1706516346-1.el8 22.04.2022 SB2021042333
SB2022042228
SB2022072038
and 15 more


Showing elements 21 - 40 out of 232