Known vulnerabilities in jenkins-2-plugins (Red Hat package) - page 3

Software CPE: cpe:2.3:o:red_hat:jenkins-2-plugins_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 232
Public exploits: 16
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting jenkins-2-plugins (Red Hat package) jenkins-2-plugins (Red Hat package) is affected by 232 known vulnerabilities: 30 high, 125 medium, 77 low Critical High Medium Low

Vulnerabilities (232)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU82122 - Improper input validation
CVE-2023-35116
CWE-20 Low
No
No
4.14.1706516441-1.el8 17.10.2023 SB2023101771
SB20231018117
SB2023101925
and 45 more
#VU82064 - Resource exhaustion
CVE-2023-39325
CWE-400 Medium
No
No
4.11.1698299029-1.el8, 4.12.1698294000-1.el8, 4.13.1698292274-1.el8, 4.14.1706516441-1.el8 16.10.2023 SB2023101651
SB2023101652
SB2023101653
and 341 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
4.13.1698292274-1.el8, 4.14.1706516441-1.el8 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 652 more
#VU79891 - Cross-Site Request Forgery (CSRF)
CVE-2023-40341
CWE-352 Low
No
No
4.12.1706515741-1.el8, 4.14.1706516441-1.el8 23.08.2023 SB2023082325
SB2024021216
SB2024021217
#VU79884 - Cross-Site Request Forgery (CSRF)
CVE-2023-40336
CWE-352 Low
No
No
4.14.1706516441-1.el8 23.08.2023 SB2023082322
SB2023112014
SB2024021216
#VU78257 - Session Fixation
CVE-2023-37946
CWE-384 High
No
No
4.11.1706516946-1.el8, 4.13.1706516346-1.el8, 4.14.1706516441-1.el8 14.07.2023 SB2023071418
SB2024021214
SB2024021215
and 1 more
#VU78005 - Inadequate Encryption Strength
CVE-2023-3089
CWE-326 Medium
No
No
4.10.1687341544-1.el8 06.07.2023 SB2023070602
SB2023070603
SB2023070604
and 34 more
#VU76232 - Exposure of sensitive information to an unauthorized actor
CVE-2023-32979
CWE-200 Low
No
No
4.10.1685679861-1.el8 17.05.2023 SB2023051750
SB2023062636
#VU76230 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-32977
CWE-79 Low
No
No
4.10.1685679861-1.el8, 4.11.1686831822-1.el8, 4.12.1686649756-1.el8 17.05.2023 SB2023051727
SB2023061545
SB2023061946
and 1 more
#VU75791 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-24540
CWE-94 Medium
No
No
4.10.1687341544-1.el8 08.05.2023 SB2023050814
SB2023050817
SB2023050825
and 81 more
#VU75561 - Improper input validation
CVE-2023-20860
CWE-20 Medium
No
No
4.10.1685679861-1.el8, 4.11.1686831822-1.el8, 4.12.1686649756-1.el8, 4.13.1686680473-1.el8 27.04.2023 SB2023042742
SB2023042746
SB2023050518
and 34 more
#VU73197 - Exposure of sensitive information to an unauthorized actor
CVE-2023-27904
CWE-200 Low
No
No
4.10.1680703106-1.el8, 4.11.1683009941-1.el8, 4.11.1686831822-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8, 4.12.1683009955-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1684911916-1.el8, 4.13.1686680473-1.el8 09.03.2023 SB2023030922
SB2023041270
SB2023041272
and 10 more
#VU73196 - Incorrect Default Permissions
CVE-2023-27903
CWE-276 Low
No
No
4.10.1680703106-1.el8, 4.11.1683009941-1.el8, 4.11.1686831822-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8, 4.12.1683009955-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1686680473-1.el8 09.03.2023 SB2023030922
SB2023041270
SB2023041272
and 9 more
#VU70530 - Deserialization of Untrusted Data
CVE-2022-45047
CWE-502 High
Available
No
4.9.1675668922-1.el8, 4.10.1675144701-1.el8, 4.11.1683009941-1.el8, 4.12.1675702407-1.el8, 4.12.1698294000-1.el8 28.12.2022 SB2022122828
SB2022122920
SB2023011148
and 49 more
#VU70527 - Improper input validation
CVE-2022-41966
CWE-20 Medium
Available
No
4.10.1685679861-1.el8, 4.11.1686831822-1.el8 28.12.2022 SB2022122822
SB2023011211
SB2023020616
and 53 more
#VU70385 - Deserialization of Untrusted Data
CVE-2022-1471
CWE-502 High
Available
No
4.9.1675668922-1.el8, 4.10.1675407676-1.el8, 4.11.1683009941-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8 15.12.2022 SB2022121539
SB2022121540
SB2022121928
and 124 more
#VU70334 - Allocation of Resources Without Limits or Throttling
CVE-2022-41717
CWE-770 Medium
Available
No
4.10.1687341544-1.el8 14.12.2022 SB2022121432
SB2022121433
SB2022121435
and 185 more
#VU68601 - Cross-Site Request Forgery (CSRF)
CVE-2022-43408
CWE-352 Low
No
No
4.9.1675668922-1.el8, 4.10.1675144701-1.el8, 4.11.1683009941-1.el8, 4.12.1675702407-1.el8, 4.12.1698294000-1.el8 24.10.2022 SB2022102418
SB2023020889
SB2023022307
and 4 more
#VU68600 - Cross-Site Request Forgery (CSRF)
CVE-2022-43407
CWE-352 Low
No
No
4.9.1675668922-1.el8, 4.10.1675144701-1.el8, 4.11.1683009941-1.el8, 4.12.1675702407-1.el8, 4.12.1698294000-1.el8 24.10.2022 SB2022102419
SB2023020889
SB2023022307
and 4 more
#VU68598 - Protection Mechanism Failure
CVE-2022-43405
CWE-693 Medium
No
No
4.9.1675668922-1.el8, 4.10.1675144701-1.el8, 4.11.1683009941-1.el8, 4.12.1675702407-1.el8, 4.12.1698294000-1.el8 24.10.2022 SB2022102422
SB2023020889
SB2023022307
and 4 more


Showing elements 41 - 60 out of 232