Vulnerabilities > Jenkins

DATE CVE VULNERABILITY TITLE RISK
2022-10-19 CVE-2022-43408 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Pipeline:Stage View
Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.
network
low complexity
jenkins CWE-352
6.5
2022-10-19 CVE-2022-43409 Cross-site Scripting vulnerability in Jenkins Pipeline: Supporting Apis 838.Va3A087B4055B
Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.
network
low complexity
jenkins CWE-79
5.4
2022-10-19 CVE-2022-43410 Unspecified vulnerability in Jenkins Mercurial
Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or scheduled for polling through its webhook endpoint, including jobs the user has no permission to access.
network
low complexity
jenkins
5.3
2022-10-19 CVE-2022-43411 Information Exposure Through Discrepancy vulnerability in Jenkins Gitlab
Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.
network
low complexity
jenkins CWE-203
5.3
2022-10-19 CVE-2022-43412 Information Exposure Through Discrepancy vulnerability in Jenkins Generic Webhook Trigger
Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.
network
low complexity
jenkins CWE-203
5.3
2022-10-19 CVE-2022-43413 Missing Authorization vulnerability in Jenkins JOB Import
Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
4.3
2022-10-19 CVE-2022-43414 Unspecified vulnerability in Jenkins Nunit
Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specified directory as test results, allowing attackers able to control agent processes to obtain test results from files in an attacker-specified directory on the Jenkins controller.
network
low complexity
jenkins
5.3
2022-10-19 CVE-2022-43415 XXE vulnerability in Jenkins Repo 1.14.0/1.15.0
Jenkins REPO Plugin 1.15.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
7.5
2022-10-19 CVE-2022-43416 Unspecified vulnerability in Jenkins Katalon
Jenkins Katalon Plugin 1.0.32 and earlier implements an agent/controller message that does not limit where it can be executed and allows invoking Katalon with configurable arguments, allowing attackers able to control agent processes to invoke Katalon on the Jenkins controller with attacker-controlled version, install location, and arguments, and attackers additionally able to create files on the Jenkins controller (e.g., attackers with Item/Configure permission could archive artifacts) to invoke arbitrary OS commands.
network
low complexity
jenkins
8.8
2022-10-19 CVE-2022-43417 Missing Authorization vulnerability in Jenkins Katalon
Jenkins Katalon Plugin 1.0.32 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
4.3