Known vulnerabilities in jenkins (Red Hat package) - page 6

Software CPE: cpe:2.3:o:red_hat:jenkins_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 221
Public exploits: 17
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting jenkins (Red Hat package) jenkins (Red Hat package) is affected by 221 known vulnerabilities: 26 high, 113 medium, 82 low Critical High Medium Low

Vulnerabilities (221)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU65851 - Information Exposure Through Timing Discrepancy
CVE-2022-36885
CWE-208 Low
No
No
2.361.1.1672840472-1.el8, 2.361.1.1675668150-1.el8 28.07.2022 SB2022072818
SB2023011328
SB2023020889
and 2 more
#VU65850 - Exposure of sensitive information to an unauthorized actor
CVE-2022-36884
CWE-200 Medium
No
No
2.361.1.1672840472-1.el8, 2.361.1.1675668150-1.el8 28.07.2022 SB2022072817
SB2023011328
SB2023020889
and 2 more
#VU65848 - Missing Authorization
CVE-2022-36883
CWE-862 Medium
No
No
2.361.1.1672840472-1.el8, 2.361.1.1675668150-1.el8 28.07.2022 SB2022072817
SB2023011328
SB2023020889
and 2 more
#VU65847 - Cross-Site Request Forgery (CSRF)
CVE-2022-36882
CWE-352 Low
No
No
2.361.1.1672840472-1.el8, 2.361.1.1675668150-1.el8 28.07.2022 SB2022072817
SB2023011328
SB2023020889
and 2 more
#VU65843 - Improper input validation
CVE-2022-36881
CWE-20 Medium
No
No
2.346.1.1667459710-1.el8, 2.361.1.1672840472-1.el8 28.07.2022 SB2022072812
SB2022111850
SB2022120619
and 1 more
#VU65830 - Resource Management Errors
CVE-2022-2048
CWE-399 Medium
No
No
2.361.1.1672840472-1.el8, 2.361.1.1675668150-1.el8, 2.401.1.1686831596-3.el8 27.07.2022 SB2022072723
SB2022080103
SB2022080260
and 44 more
#VU64608 - Improper input validation
CVE-2022-34177
CWE-20 Medium
No
No
2.346.3.1663151230-1.el8, 2.361.1.1669892772-1.el8, 2.361.1.1672840472-1.el8 23.06.2022 SB2022062315
SB2022092149
SB2023010903
and 2 more
#VU64607 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-34176
CWE-79 Low
No
No
2.346.1.1667459710-1.el8, 2.361.1.1672840472-1.el8 23.06.2022 SB2022062313
SB2022120619
SB2023011328
#VU64604 - Observable discrepancy
CVE-2022-34174
CWE-203 Medium
No
No
2.361.1.1672840472-1.el8, 2.361.1.1675406172-1.el8, 2.361.1.1675668150-1.el8 23.06.2022 SB2022062312
SB2023011328
SB2023021602
and 5 more
#VU63377 - Improper Access Control
CVE-2022-30954
CWE-284 Low
No
No
2.361.1.1672840472-1.el8, 2.361.1.1675668150-1.el8, 2.387.1.1683009763-3.el8, 2.401.1.1686649641-3.el8, 2.401.1.1686680404-3.el8 18.05.2022 SB2022051814
SB2023011328
SB2023020889
and 5 more
#VU63375 - Cross-Site Request Forgery (CSRF)
CVE-2022-30953
CWE-352 Low
No
No
2.361.1.1672840472-1.el8, 2.361.1.1675668150-1.el8, 2.387.1.1683009763-3.el8, 2.401.1.1686649641-3.el8, 2.401.1.1686680404-3.el8 18.05.2022 SB2022051814
SB2023011328
SB2023020889
and 5 more
#VU63363 - Exposure of sensitive information to an unauthorized actor
CVE-2022-30948
CWE-200 Low
No
No
2.361.1.1672840472-1.el8 18.05.2022 SB2022051810
SB2023011328
#VU63359 - Cross-Site Request Forgery (CSRF)
CVE-2022-30946
CWE-352 Low
No
No
2.361.1.1672840472-1.el8, 2.361.1.1675668150-1.el8 18.05.2022 SB2022051808
SB2023011328
SB2023020889
and 4 more
#VU63358 - Security Features
CVE-2022-30945
CWE-254 Medium
No
No
2.361.1.1672840472-1.el8 18.05.2022 SB2022051806
SB2023011328
#VU62796 - Incorrect Default Permissions
CVE-2022-27652
CWE-276 Low
No
No
2.319.3.1650888800-1.el8 04.05.2022 SB2022050416
SB2022050422
SB2022080148
and 1 more
#VU62304 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-29046
CWE-79 Low
No
No
2.319.3.1651752848-1.el8 13.04.2022 SB2022041333
SB2022053122
SB2022061218
and 3 more
#VU62299 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-29041
CWE-79 Low
No
No
2.319.3.1651752848-1.el8 13.04.2022 SB2022041328
SB2022051924
#VU62292 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-29036
CWE-79 Low
No
No
2.319.3.1651752848-1.el8 13.04.2022 SB2022041321
SB2022053122
SB2022061218
and 2 more
#VU60643 - UNIX Symbolic Link (Symlink) Following
CVE-2022-25179
CWE-61 Medium
No
No
2.319.3.1650348949-1.el7 16.02.2022 SB2022021608
SB2022032826
SB2022032910
and 4 more
#VU60640 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-25182
CWE-94 Medium
No
No
2.319.3.1650348949-1.el7 16.02.2022 SB2022021607
SB2022032826
SB2022032910
and 4 more


Showing elements 101 - 120 out of 221