Known vulnerabilities in jenkins-2-plugins (Red Hat package) - page 6

Software CPE: cpe:2.3:o:red_hat:jenkins-2-plugins_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 232
Public exploits: 16
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting jenkins-2-plugins (Red Hat package) jenkins-2-plugins (Red Hat package) is affected by 232 known vulnerabilities: 30 high, 125 medium, 77 low Critical High Medium Low

Vulnerabilities (232)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU69368 -
CVE-2022-45379
Medium
No
No
4.9.1675668922-1.el8, 4.10.1675144701-1.el8 16.11.2022 SB2022111616
SB2023020889
SB2023022307
and 3 more
#VU65851 - Information Exposure Through Timing Discrepancy
CVE-2022-36885
CWE-208 Low
No
No
4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.10.1675144701-1.el8 28.07.2022 SB2022072818
SB2023011328
SB2023020889
and 2 more
#VU65850 - Exposure of sensitive information to an unauthorized actor
CVE-2022-36884
CWE-200 Medium
No
No
4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.10.1675144701-1.el8 28.07.2022 SB2022072817
SB2023011328
SB2023020889
and 2 more
#VU65848 - Missing Authorization
CVE-2022-36883
CWE-862 Medium
No
No
4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.10.1675144701-1.el8 28.07.2022 SB2022072817
SB2023011328
SB2023020889
and 2 more
#VU65847 - Cross-Site Request Forgery (CSRF)
CVE-2022-36882
CWE-352 Low
No
No
4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.10.1675144701-1.el8 28.07.2022 SB2022072817
SB2023011328
SB2023020889
and 2 more
#VU65843 - Improper input validation
CVE-2022-36881
CWE-20 Medium
No
No
4.8.1672842762-1.el8, 4.9.1667460322-1.el8, 4.10.1667388055-1.el8 28.07.2022 SB2022072812
SB2022111850
SB2022120619
and 1 more
#VU64608 - Improper input validation
CVE-2022-34177
CWE-20 Medium
No
No
4.8.1672842762-1.el8, 4.9.1669894222-1.el8, 4.10.1663147786-1.el8 23.06.2022 SB2022062315
SB2022092149
SB2023010903
and 2 more
#VU64607 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-34176
CWE-79 Low
No
No
4.8.1672842762-1.el8, 4.9.1667460322-1.el8 23.06.2022 SB2022062313
SB2022120619
SB2023011328
#VU64604 - Observable discrepancy
CVE-2022-34174
CWE-203 Medium
No
No
4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.10.1675407676-1.el8 23.06.2022 SB2022062312
SB2023011328
SB2023021602
and 5 more
#VU64008 - Resource exhaustion
CVE-2022-1708
CWE-400 Medium
No
No
4.6.1653312933-1.el8 07.06.2022 SB2022060707
SB2022061334
SB2022061627
and 15 more
#VU63363 - Exposure of sensitive information to an unauthorized actor
CVE-2022-30948
CWE-200 Low
No
No
4.8.1672842762-1.el8 18.05.2022 SB2022051810
SB2023011328
#VU63359 - Cross-Site Request Forgery (CSRF)
CVE-2022-30946
CWE-352 Low
No
No
4.8.1672842762-1.el8, 4.9.1675668922-1.el8, 4.10.1675144701-1.el8 18.05.2022 SB2022051808
SB2023011328
SB2023020889
and 4 more
#VU63358 - Security Features
CVE-2022-30945
CWE-254 Medium
No
No
4.8.1672842762-1.el8 18.05.2022 SB2022051806
SB2023011328
#VU62305 - Improper Access Control
CVE-2022-29047
CWE-284 Medium
No
No
4.7.1652967082-1.el8, 4.8.1672842762-1.el8, 4.9.1651754460-1.el8, 4.12.1675702407-1.el8 13.04.2022 SB2022041334
SB2022061218
SB2023011328
and 2 more
#VU62304 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-29046
CWE-79 Low
No
No
4.6.1653312933-1.el8, 4.7.1652967082-1.el8, 4.9.1651754460-1.el8 13.04.2022 SB2022041333
SB2022053122
SB2022061218
and 3 more
#VU62299 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-29041
CWE-79 Low
No
No
4.9.1651754460-1.el8 13.04.2022 SB2022041328
SB2022051924
#VU62292 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-29036
CWE-79 Low
No
No
4.6.1653312933-1.el8, 4.7.1652967082-1.el8, 4.9.1651754460-1.el8 13.04.2022 SB2022041321
SB2022053122
SB2022061218
and 2 more
#VU60643 - UNIX Symbolic Link (Symlink) Following
CVE-2022-25179
CWE-61 Medium
No
No
3.11.1650371376-1.el7, 4.6.1650364520-1.el8, 4.7.1648800585-1.el8, 4.9.1647580879-1.el8, 4.10.1647505461-1.el8 16.02.2022 SB2022021608
SB2022032826
SB2022032910
and 4 more
#VU60640 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-25182
CWE-94 Medium
No
No
3.11.1650371376-1.el7, 4.6.1650364520-1.el8, 4.7.1648800585-1.el8, 4.9.1647580879-1.el8, 4.10.1647505461-1.el8 16.02.2022 SB2022021607
SB2022032826
SB2022032910
and 4 more
#VU60636 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-25174
CWE-78 Medium
No
No
3.11.1650371376-1.el7, 4.6.1650364520-1.el8, 4.7.1648800585-1.el8, 4.9.1647580879-1.el8, 4.10.1647505461-1.el8 16.02.2022 SB2022021607
SB2022032826
SB2022032910
and 4 more


Showing elements 101 - 120 out of 232