Known vulnerabilities in jenkins (Red Hat package) - page 3

Software CPE: cpe:2.3:o:red_hat:jenkins_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 221
Public exploits: 17
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting jenkins (Red Hat package) jenkins (Red Hat package) is affected by 221 known vulnerabilities: 26 high, 113 medium, 82 low Critical High Medium Low

Vulnerabilities (221)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU76236 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-32981
CWE-22 Medium
No
No
2.401.1.1685677065-1.el8, 2.401.1.1686649641-3.el8, 2.401.1.1686831596-3.el8 17.05.2023 SB2023051751
SB2023061545
SB2023061946
and 1 more
#VU76234 - Cross-Site Request Forgery (CSRF)
CVE-2023-32980
CWE-352 Low
No
No
2.401.1.1685677065-1.el8 17.05.2023 SB2023051750
SB2023062636
#VU76230 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-32977
CWE-79 Low
No
No
2.401.1.1685677065-1.el8, 2.401.1.1686649641-3.el8, 2.401.1.1686831596-3.el8 17.05.2023 SB2023051727
SB2023061545
SB2023061946
and 1 more
#VU75562 - Improper input validation
CVE-2023-20861
CWE-20 Medium
No
No
2.401.1.1686649641-3.el8, 2.401.1.1686680404-3.el8, 2.426.3.1706515686-3.el8 27.04.2023 SB2023042742
SB2023042746
SB2023042832
and 61 more
#VU75561 - Improper input validation
CVE-2023-20860
CWE-20 Medium
No
No
2.401.1.1685677065-1.el8, 2.401.1.1686649641-3.el8, 2.401.1.1686680404-3.el8, 2.401.1.1686831596-3.el8 27.04.2023 SB2023042742
SB2023042746
SB2023050518
and 34 more
#VU75431 - Uncontrolled Recursion
CVE-2023-1436
CWE-674 Medium
No
No
2.401.1.1686680404-3.el8, 2.401.1.1686831596-3.el8 24.04.2023 SB2023042409
SB2023042411
SB2023050111
and 86 more
#VU75044 - Uncontrolled Recursion
CVE-2023-1370
CWE-674 Medium
No
No
2.401.1.1686649641-3.el8, 2.401.1.1686680404-3.el8, 2.401.1.1686831596-3.el8, 2.504.2.1750846524-3.el9, 2.504.2.1750851690-3.el9, 2.504.2.1750856366-3.el8, 2.504.2.1750857144-3.el9, 2.504.2.1750903189-3.el8, 2.504.2.1750916374-3.el8, 2.504.2.1750932984-3.el8 12.04.2023 SB2023041258
SB2023041259
SB2023041809
and 130 more
#VU73244 - Resource exhaustion
CVE-2023-26464
CWE-400 Medium
No
No
2.401.1.1686831596-3.el8 10.03.2023 SB2023031040
SB2023032716
SB2023050514
and 22 more
#VU73196 - Incorrect Default Permissions
CVE-2023-27903
CWE-276 Low
No
No
2.387.1.1680701869-1.el8, 2.387.1.1683009763-3.el8, 2.387.1.1683009767-3.el8, 2.401.1.1686680404-3.el8, 2.401.1.1686831596-3.el8, 2.414.3.1698293911-3.el8, 2.414.3.1698298955-3.el8, 2.426.3.1706515686-3.el8, 2.426.3.1706516929-3.el8 09.03.2023 SB2023030922
SB2023041270
SB2023041272
and 9 more
#VU73188 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-27899
CWE-94 Medium
No
No
2.387.1.1680701869-1.el8, 2.401.1.1686831596-3.el8 09.03.2023 SB2023030922
SB2023041270
SB2023041272
and 2 more
#VU73187 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-27898
CWE-79 Low
No
No
2.387.1.1680701869-1.el8, 2.401.1.1686831596-3.el8 09.03.2023 SB2023030922
SB2023041270
SB2023041272
and 2 more
#VU72686 - Resource exhaustion
CVE-2022-41723
CWE-400 Medium
No
No
2.401.1.1686649641-3.el8 01.03.2023 SB2023030130
SB2023030131
SB2023030946
and 190 more
#VU71499 - Permissions, Privileges, and Access Controls
CVE-2023-24422
CWE-264 Medium
No
No
2.387.1.1680701869-1.el8, 2.387.1.1683009763-3.el8, 2.387.1.1683009767-3.el8, 2.387.3.1684911776-3.el8, 2.401.1.1686649641-3.el8, 2.414.3.1698292201-3.el8, 2.414.3.1698293911-3.el8, 2.414.3.1698298955-3.el8, 2.426.3.1706515686-3.el8, 2.426.3.1706516254-3.el8, 2.426.3.1706516352-3.el8, 2.426.3.1706516929-3.el8 25.01.2023 SB2023012504
SB2023041270
SB2023041272
and 14 more
#VU71109 - Out-of-bounds write
CVE-2022-45693
CWE-787 Medium
No
No
2.401.1.1686649641-3.el8 11.01.2023 SB2023011159
SB2023011160
SB2023013112
and 45 more
#VU70527 - Improper input validation
CVE-2022-41966
CWE-20 Medium
Available
No
2.401.1.1685677065-1.el8, 2.401.1.1686831596-3.el8 28.12.2022 SB2022122822
SB2023011211
SB2023020616
and 53 more
#VU69674 - Resource exhaustion
CVE-2022-40150
CWE-400 Medium
No
No
2.401.1.1686649641-3.el8, 2.401.1.1686831596-3.el8 29.11.2022 SB2022112909
SB2022112941
SB2022121101
and 46 more
#VU69673 - Out-of-bounds write
CVE-2022-40149
CWE-787 Medium
No
No
2.401.1.1686649641-3.el8, 2.401.1.1686831596-3.el8 29.11.2022 SB2022112909
SB2022112941
SB2022121101
and 41 more
#VU63342 - Integer overflow
CVE-2022-22976
CWE-190 Low
Available
No
2.401.1.1686831596-3.el8 17.05.2022 SB2022051717
SB2022052009
SB2022052010
and 7 more
#VU62608 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-29599
CWE-78 High
No
No
2.387.1.1683009763-3.el8, 2.401.1.1686649641-3.el8, 2.401.1.1686680404-3.el8, 2.414.3.1698292201-3.el8, 2.414.3.1698293911-3.el8, 2.414.3.1698298955-3.el8, 2.426.3.1706515686-3.el8, 2.426.3.1706516254-3.el8, 2.426.3.1706516352-3.el8, 2.426.3.1706516929-3.el8 26.04.2022 SB2022042627
SB2022042724
SB2022050234
and 29 more
#VU59148 - Deserialization of Untrusted Data
CVE-2021-46877
CWE-502 Medium
No
No
2.387.3.1684911776-3.el8, 2.401.1.1686649641-3.el8 03.01.2022 SB2022010326
SB2022010327
SB2022062734
and 37 more


Showing elements 41 - 60 out of 221