Known vulnerabilities in jenkins (Red Hat package) - page 2

Software CPE: cpe:2.3:o:red_hat:jenkins_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 221
Public exploits: 17
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting jenkins (Red Hat package) jenkins (Red Hat package) is affected by 221 known vulnerabilities: 26 high, 113 medium, 82 low Critical High Medium Low

Vulnerabilities (221)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU85790 - Missing Origin Validation in WebSockets
CVE-2024-23898
CWE-1385 High
Available
No
2.426.3.1706515686-3.el8, 2.426.3.1706516254-3.el8, 2.426.3.1706516929-3.el8 25.01.2024 SB2024012513
SB2024021214
SB2024021215
and 1 more
#VU85786 - Improper Access Control
CVE-2024-23897
CWE-284 High
Available
Exploited
2.426.3.1706515686-3.el8, 2.426.3.1706516254-3.el8, 2.426.3.1706516929-3.el8 25.01.2024 SB2024012513
SB2024021214
SB2024021215
and 6 more
#VU82122 - Improper input validation
CVE-2023-35116
CWE-20 Low
No
No
2.426.3.1706516352-3.el8 17.10.2023 SB2023101771
SB20231018117
SB2023101925
and 45 more
#VU82064 - Resource exhaustion
CVE-2023-39325
CWE-400 Medium
No
No
2.414.3.1698292201-3.el8, 2.414.3.1698293911-3.el8, 2.414.3.1698298955-3.el8, 2.426.3.1706516352-3.el8 16.10.2023 SB2023101651
SB2023101652
SB2023101653
and 341 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
2.414.3.1698292201-3.el8, 2.426.3.1706516352-3.el8 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 650 more
#VU80791 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-40167
CWE-444 Medium
No
No
2.426.3.1706515686-3.el8 14.09.2023 SB2023091440
SB2023092933
SB2023101760
and 68 more
#VU79891 - Cross-Site Request Forgery (CSRF)
CVE-2023-40341
CWE-352 Low
No
No
2.426.3.1706515686-3.el8, 2.426.3.1706516352-3.el8 23.08.2023 SB2023082325
SB2024021216
SB2024021217
#VU79888 - Exposure of sensitive information to an unauthorized actor
CVE-2023-40339
CWE-200 Low
No
No
2.426.3.1706515686-3.el8, 2.426.3.1706516352-3.el8 23.08.2023 SB2023082323
SB2023112014
SB2024021216
and 1 more
#VU79886 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-40338
CWE-22 Low
No
No
2.426.3.1706515686-3.el8, 2.426.3.1706516352-3.el8 23.08.2023 SB2023082322
SB2023112014
SB2024021216
and 1 more
#VU79885 - Cross-Site Request Forgery (CSRF)
CVE-2023-40337
CWE-352 Low
No
No
2.426.3.1706515686-3.el8, 2.426.3.1706516352-3.el8 23.08.2023 SB2023082322
SB2023112014
SB2024021216
and 1 more
#VU79884 - Cross-Site Request Forgery (CSRF)
CVE-2023-40336
CWE-352 Low
No
No
2.426.3.1706516352-3.el8 23.08.2023 SB2023082322
SB2023112014
SB2024021216
#VU78258 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-37947
CWE-601 Low
No
No
2.426.3.1706515686-3.el8, 2.426.3.1706516352-3.el8 14.07.2023 SB2023071418
SB2024021216
SB2024021217
#VU78257 - Session Fixation
CVE-2023-37946
CWE-384 High
No
No
2.426.3.1706516254-3.el8, 2.426.3.1706516352-3.el8, 2.426.3.1706516929-3.el8 14.07.2023 SB2023071418
SB2024021214
SB2024021215
and 1 more
#VU78005 - Inadequate Encryption Strength
CVE-2023-3089
CWE-326 Medium
No
No
2.401.1.1687268694-1.el8 06.07.2023 SB2023070602
SB2023070603
SB2023070604
and 34 more
#VU77107 - Incorrect Default Permissions
CVE-2023-2976
CWE-276 Low
No
No
2.426.3.1706515686-3.el8, 2.426.3.1706516352-3.el8 08.06.2023 SB2023060849
SB2023071712
SB2023072512
and 157 more
#VU76232 - Exposure of sensitive information to an unauthorized actor
CVE-2023-32979
CWE-200 Low
No
No
2.401.1.1685677065-1.el8 17.05.2023 SB2023051750
SB2023062636
#VU75791 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-24540
CWE-94 Medium
No
No
2.401.1.1687268694-1.el8 08.05.2023 SB2023050814
SB2023050817
SB2023050825
and 81 more
#VU75218 - Resource exhaustion
CVE-2023-26048
CWE-400 Medium
No
No
2.426.3.1706515686-3.el8 18.04.2023 SB2023041842
SB2023051753
SB2023060701
and 55 more
#VU75217 - Improper input validation
CVE-2023-26049
CWE-20 Low
No
No
2.426.3.1706515686-3.el8 18.04.2023 SB2023041842
SB2023051821
SB2023060836
and 78 more
#VU70334 - Allocation of Resources Without Limits or Throttling
CVE-2022-41717
CWE-770 Medium
Available
No
2.401.1.1687268694-1.el8 14.12.2022 SB2022121432
SB2022121433
SB2022121435
and 185 more


Showing elements 21 - 40 out of 221