Known vulnerabilities in jenkins-2-plugins (Red Hat package) - page 3

Software CPE: cpe:2.3:o:red_hat:jenkins-2-plugins_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 232
Public exploits: 16
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting jenkins-2-plugins (Red Hat package) jenkins-2-plugins (Red Hat package) is affected by 232 known vulnerabilities: 30 high, 125 medium, 77 low Critical High Medium Low

Vulnerabilities (232)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU76236 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-32981
CWE-22 Medium
No
No
4.10.1685679861-1.el8, 4.11.1686831822-1.el8, 4.12.1686649756-1.el8 17.05.2023 SB2023051751
SB2023061545
SB2023061946
and 1 more
#VU76234 - Cross-Site Request Forgery (CSRF)
CVE-2023-32980
CWE-352 Low
No
No
4.10.1685679861-1.el8 17.05.2023 SB2023051750
SB2023062636
#VU76230 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-32977
CWE-79 Low
No
No
4.10.1685679861-1.el8, 4.11.1686831822-1.el8, 4.12.1686649756-1.el8 17.05.2023 SB2023051727
SB2023061545
SB2023061946
and 1 more
#VU75562 - Improper input validation
CVE-2023-20861
CWE-20 Medium
No
No
4.12.1686649756-1.el8, 4.12.1706515741-1.el8, 4.13.1686680473-1.el8 27.04.2023 SB2023042742
SB2023042746
SB2023042832
and 61 more
#VU75561 - Improper input validation
CVE-2023-20860
CWE-20 Medium
No
No
4.10.1685679861-1.el8, 4.11.1686831822-1.el8, 4.12.1686649756-1.el8, 4.13.1686680473-1.el8 27.04.2023 SB2023042742
SB2023042746
SB2023050518
and 34 more
#VU75431 - Uncontrolled Recursion
CVE-2023-1436
CWE-674 Medium
No
No
4.11.1686831822-1.el8, 4.13.1686680473-1.el8 24.04.2023 SB2023042409
SB2023042411
SB2023050111
and 86 more
#VU75044 - Uncontrolled Recursion
CVE-2023-1370
CWE-674 Medium
No
No
4.11.1686831822-1.el8, 4.12.1686649756-1.el8, 4.12.1750933270-1.el8, 4.13.1686680473-1.el8, 4.13.1750916671-1.el8, 4.14.1750903529-1.el8, 4.15.1750856638-1.el8, 4.16.1750857315-1.el9, 4.17.1750851950-1.el9, 4.18.1750846854-1.el9 12.04.2023 SB2023041258
SB2023041259
SB2023041809
and 130 more
#VU73244 - Resource exhaustion
CVE-2023-26464
CWE-400 Medium
No
No
4.11.1686831822-1.el8 10.03.2023 SB2023031040
SB2023032716
SB2023050514
and 22 more
#VU73197 - Exposure of sensitive information to an unauthorized actor
CVE-2023-27904
CWE-200 Low
No
No
4.10.1680703106-1.el8, 4.11.1683009941-1.el8, 4.11.1686831822-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8, 4.12.1683009955-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1684911916-1.el8, 4.13.1686680473-1.el8 09.03.2023 SB2023030922
SB2023041270
SB2023041272
and 10 more
#VU73196 - Incorrect Default Permissions
CVE-2023-27903
CWE-276 Low
No
No
4.10.1680703106-1.el8, 4.11.1683009941-1.el8, 4.11.1686831822-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8, 4.12.1683009955-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1686680473-1.el8 09.03.2023 SB2023030922
SB2023041270
SB2023041272
and 9 more
#VU73188 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-27899
CWE-94 Medium
No
No
4.10.1680703106-1.el8, 4.11.1686831822-1.el8 09.03.2023 SB2023030922
SB2023041270
SB2023041272
and 2 more
#VU73187 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-27898
CWE-79 Low
No
No
4.10.1680703106-1.el8, 4.11.1686831822-1.el8 09.03.2023 SB2023030922
SB2023041270
SB2023041272
and 2 more
#VU72686 - Resource exhaustion
CVE-2022-41723
CWE-400 Medium
No
No
4.12.1686649756-1.el8 01.03.2023 SB2023030130
SB2023030131
SB2023030946
and 190 more
#VU71499 - Permissions, Privileges, and Access Controls
CVE-2023-24422
CWE-264 Medium
No
No
4.10.1680703106-1.el8, 4.11.1683009941-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8, 4.12.1683009955-1.el8, 4.12.1686649756-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1684911916-1.el8, 4.13.1698292274-1.el8, 4.13.1706516346-1.el8, 4.14.1706516441-1.el8 25.01.2023 SB2023012504
SB2023041270
SB2023041272
and 14 more
#VU71109 - Out-of-bounds write
CVE-2022-45693
CWE-787 Medium
No
No
4.12.1686649756-1.el8 11.01.2023 SB2023011159
SB2023011160
SB2023013112
and 45 more
#VU70527 - Improper input validation
CVE-2022-41966
CWE-20 Medium
Available
No
4.10.1685679861-1.el8, 4.11.1686831822-1.el8 28.12.2022 SB2022122822
SB2023011211
SB2023020616
and 53 more
#VU69674 - Resource exhaustion
CVE-2022-40150
CWE-400 Medium
No
No
4.11.1686831822-1.el8, 4.12.1686649756-1.el8 29.11.2022 SB2022112909
SB2022112941
SB2022121101
and 46 more
#VU69673 - Out-of-bounds write
CVE-2022-40149
CWE-787 Medium
No
No
4.11.1686831822-1.el8, 4.12.1686649756-1.el8 29.11.2022 SB2022112909
SB2022112941
SB2022121101
and 41 more
#VU63342 - Integer overflow
CVE-2022-22976
CWE-190 Low
Available
No
4.11.1686831822-1.el8 17.05.2022 SB2022051717
SB2022052009
SB2022052010
and 7 more
#VU59148 - Deserialization of Untrusted Data
CVE-2021-46877
CWE-502 Medium
No
No
4.12.1686649756-1.el8, 4.13.1684911916-1.el8 03.01.2022 SB2022010326
SB2022010327
SB2022062734
and 37 more


Showing elements 41 - 60 out of 232