Known vulnerabilities in jenkins-2-plugins (Red Hat package) - page 6

Software CPE: cpe:2.3:o:red_hat:jenkins-2-plugins_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 232
Public exploits: 16
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting jenkins-2-plugins (Red Hat package) jenkins-2-plugins (Red Hat package) is affected by 232 known vulnerabilities: 30 high, 125 medium, 77 low Critical High Medium Low

Vulnerabilities (232)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU67665 - Resource exhaustion
CVE-2022-25857
CWE-400 Medium
No
No
4.9.1675668922-1.el8, 4.10.1675144701-1.el8, 4.11.1683009941-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1698292274-1.el8, 4.13.1706516346-1.el8, 4.14.1706516441-1.el8 27.09.2022 SB2022092714
SB2022092728
SB2022100555
and 83 more
#VU65848 - Missing Authorization
CVE-2022-36883
CWE-862 Medium
No
No
4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.10.1675144701-1.el8 28.07.2022 SB2022072817
SB2023011328
SB2023020889
and 2 more
#VU65847 - Cross-Site Request Forgery (CSRF)
CVE-2022-36882
CWE-352 Low
No
No
4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.10.1675144701-1.el8 28.07.2022 SB2022072817
SB2023011328
SB2023020889
and 2 more
#VU65843 - Improper input validation
CVE-2022-36881
CWE-20 Medium
No
No
4.8.1672842762-1.el8, 4.9.1667460322-1.el8, 4.10.1667388055-1.el8 28.07.2022 SB2022072812
SB2022111850
SB2022120619
and 1 more
#VU65830 - Resource Management Errors
CVE-2022-2048
CWE-399 Medium
No
No
4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.11.1686831822-1.el8 27.07.2022 SB2022072723
SB2022080103
SB2022080260
and 44 more
#VU64608 - Improper input validation
CVE-2022-34177
CWE-20 Medium
No
No
4.8.1672842762-1.el8, 4.9.1669894222-1.el8, 4.10.1663147786-1.el8 23.06.2022 SB2022062315
SB2022092149
SB2023010903
and 2 more
#VU64607 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-34176
CWE-79 Low
No
No
4.8.1672842762-1.el8, 4.9.1667460322-1.el8 23.06.2022 SB2022062313
SB2022120619
SB2023011328
#VU64604 - Observable discrepancy
CVE-2022-34174
CWE-203 Medium
No
No
4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.10.1675407676-1.el8 23.06.2022 SB2022062312
SB2023011328
SB2023021602
and 5 more
#VU64008 - Resource exhaustion
CVE-2022-1708
CWE-400 Medium
No
No
4.6.1653312933-1.el8 07.06.2022 SB2022060707
SB2022061334
SB2022061627
and 15 more
#VU63377 - Improper Access Control
CVE-2022-30954
CWE-284 Low
No
No
4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.10.1675144701-1.el8, 4.11.1683009941-1.el8, 4.12.1686649756-1.el8, 4.13.1686680473-1.el8 18.05.2022 SB2022051814
SB2023011328
SB2023020889
and 5 more
#VU63375 - Cross-Site Request Forgery (CSRF)
CVE-2022-30953
CWE-352 Low
No
No
4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.10.1675144701-1.el8, 4.11.1683009941-1.el8, 4.12.1686649756-1.el8, 4.13.1686680473-1.el8 18.05.2022 SB2022051814
SB2023011328
SB2023020889
and 5 more
#VU63363 - Exposure of sensitive information to an unauthorized actor
CVE-2022-30948
CWE-200 Low
No
No
4.8.1672842762-1.el8 18.05.2022 SB2022051810
SB2023011328
#VU63359 - Cross-Site Request Forgery (CSRF)
CVE-2022-30946
CWE-352 Low
No
No
4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.10.1675144701-1.el8 18.05.2022 SB2022051808
SB2023011328
SB2023020889
and 4 more
#VU63358 - Security Features
CVE-2022-30945
CWE-254 Medium
No
No
4.8.1672842762-1.el8 18.05.2022 SB2022051806
SB2023011328
#VU62304 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-29046
CWE-79 Low
No
No
4.6.1653312933-1.el8, 4.7.1652967082-1.el8, 4.9.1651754460-1.el8 13.04.2022 SB2022041333
SB2022053122
SB2022061218
and 3 more
#VU62299 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-29041
CWE-79 Low
No
No
4.9.1651754460-1.el8 13.04.2022 SB2022041328
SB2022051924
#VU62292 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-29036
CWE-79 Low
No
No
4.6.1653312933-1.el8, 4.7.1652967082-1.el8, 4.9.1651754460-1.el8 13.04.2022 SB2022041321
SB2022053122
SB2022061218
and 2 more
#VU60643 - UNIX Symbolic Link (Symlink) Following
CVE-2022-25179
CWE-61 Medium
No
No
3.11.1650371376-1.el7, 4.6.1650364520-1.el8, 4.7.1648800585-1.el8, 4.9.1647580879-1.el8, 4.10.1647505461-1.el8 16.02.2022 SB2022021608
SB2022032826
SB2022032910
and 4 more
#VU60640 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-25182
CWE-94 Medium
No
No
3.11.1650371376-1.el7, 4.6.1650364520-1.el8, 4.7.1648800585-1.el8, 4.9.1647580879-1.el8, 4.10.1647505461-1.el8 16.02.2022 SB2022021607
SB2022032826
SB2022032910
and 4 more
#VU60636 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-25174
CWE-78 Medium
No
No
3.11.1650371376-1.el7, 4.6.1650364520-1.el8, 4.7.1648800585-1.el8, 4.9.1647580879-1.el8, 4.10.1647505461-1.el8 16.02.2022 SB2022021607
SB2022032826
SB2022032910
and 4 more


Showing elements 101 - 120 out of 232