Known vulnerabilities in jenkins (Red Hat package) 1.625.3-2.el7aos - page 2

Version: 1.625.3-2.el7aos
Software CPE: cpe:2.3:o:red_hat:jenkins_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 41
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting jenkins (Red Hat package) version 1.625.3-2.el7aos jenkins (Red Hat package) 1.625.3-2.el7aos is affected by 41 vulnerabilities: 9 high, 14 medium, 18 low Critical High Medium Low

Vulnerabilities (41)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU52494 - Cross-Site Request Forgery (CSRF)
CVE-2021-21644
CWE-352 Low
No
No
2.263.3.1623239705-1.el8, 2.277.3.1623846768-1.el7, 2.289.1.1624365627-1.el7 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52493 - Permissions, Privileges, and Access Controls
CVE-2021-21643
CWE-264 Low
No
No
2.263.3.1623239705-1.el8, 2.277.3.1623846768-1.el7, 2.289.1.1624365627-1.el7 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU52492 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2021-21642
CWE-611 Medium
No
No
2.263.3.1623239705-1.el8, 2.277.3.1623846768-1.el7, 2.289.1.1624365627-1.el7 22.04.2021 SB2021042205
SB2021060101
SB2021063033
and 3 more
#VU50020 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2021-21615
CWE-367 Medium
No
No
2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8 26.01.2021 SB2021012623
SB2021021723
SB2021022601
and 1 more
#VU49525 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21611
CWE-79 Low
No
No
2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8 14.01.2021 SB2021011418
SB2021011453
SB2021012106
and 2 more
#VU49524 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21610
CWE-79 Low
No
No
2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8 14.01.2021 SB2021011418
SB2021011452
SB2021012106
and 2 more
#VU49523 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21608
CWE-79 Low
No
No
2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8 14.01.2021 SB2021011418
SB2021011450
SB2021012106
and 2 more
#VU49522 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21603
CWE-79 Low
No
No
2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8 13.01.2021 SB2021011418
SB2021011445
SB2021012106
and 2 more
#VU49526 - XML Injection
CVE-2021-21604
CWE-91 Medium
No
No
2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8 13.01.2021 SB2021011418
SB2021011446
SB2021012106
and 2 more
#VU49527 - Exposure of sensitive information to an unauthorized actor
CVE-2021-21602
CWE-200 Medium
No
No
2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8 13.01.2021 SB2021011418
SB2021011444
SB2021012106
and 2 more
#VU49528 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-21605
CWE-22 Medium
No
No
2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8 13.01.2021 SB2021011418
SB2021011447
SB2021012106
and 2 more
#VU49529 - Permissions, Privileges, and Access Controls
CVE-2021-21606
CWE-264 Low
No
No
2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8 13.01.2021 SB2021011418
SB2021011448
SB2021012106
and 2 more
#VU49530 - Memory corruption
CVE-2021-21607
CWE-119 Medium
No
No
2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8 13.01.2021 SB2021011418
SB2021011449
SB2021012106
and 2 more
#VU49531 - Permissions, Privileges, and Access Controls
CVE-2021-21609
CWE-264 Low
No
No
2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8 13.01.2021 SB2021011418
SB2021011451
SB2021012106
and 2 more
#VU34052 - Resource exhaustion
CVE-2020-8557
CWE-400 Low
No
No
2.235.2.1597312414-1.el7, 2.235.5.1600415514-1.el7 23.07.2020 SB2020072349
SB2020082409
SB2021110213
and 2 more
#VU30129 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2223
CWE-79 Low
No
No
2.235.2.1597312065-1.el7, 2.235.2.1597312414-1.el7, 2.235.5.1600415514-1.el7 16.07.2020 SB20200716112
SB2020082409
SB2020071911
and 2 more
#VU30128 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2222
CWE-79 Low
No
No
2.235.2.1597312065-1.el7, 2.235.2.1597312414-1.el7, 2.235.5.1600415514-1.el7 16.07.2020 SB20200716112
SB2020082409
SB2020071910
and 2 more
#VU30127 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-2221
CWE-79 Low
No
No
2.235.2.1597312065-1.el7, 2.235.2.1597312414-1.el7, 2.235.5.1600415514-1.el7 16.07.2020 SB20200716112
SB2020082409
SB2020071909
and 2 more
#VU27924 - Incorrect Default Permissions
CVE-2020-1945
CWE-276 Low
No
No
2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8 15.05.2020 SB2020051501
SB2020052114
SB2020060205
and 48 more
#VU47428 - Permissions, Privileges, and Access Controls
CVE-2020-11979
CWE-264 Low
No
No
2.263.3.1612434332-1.el7, 2.263.3.1612434510-1.el8 14.05.2020 SB2020100804
SB2020100815
SB2020111614
and 51 more


Showing elements 21 - 40 out of 41