Vulnerabilities > Jenkins > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-01-26 CVE-2023-24430 XXE vulnerability in Jenkins Semantic Versioning
Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
critical
9.8
2023-01-26 CVE-2023-24429 XXE vulnerability in Jenkins Semantic Versioning
Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitations about the file path that can be parsed, allowing attackers able to control agent processes to have Jenkins parse a crafted file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
network
low complexity
jenkins CWE-611
critical
9.8
2023-01-26 CVE-2023-24427 Session Fixation vulnerability in Jenkins Bitbucket Oauth
Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.
network
low complexity
jenkins CWE-384
critical
9.8
2022-12-12 CVE-2022-46682 XXE vulnerability in Jenkins Plot
Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
critical
9.8
2022-11-15 CVE-2022-45400 XXE vulnerability in Jenkins Japex 1.7
Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
critical
9.8
2022-11-15 CVE-2022-45397 XXE vulnerability in Jenkins OSF Builder Suite :: XML Linter 1.0.2
Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
critical
9.8
2022-11-15 CVE-2022-45396 XXE vulnerability in Jenkins Sourcemonitor 0.2
Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
critical
9.8
2022-11-15 CVE-2022-45395 XXE vulnerability in Jenkins Cccc
Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
critical
9.8
2022-10-19 CVE-2022-43406 Unspecified vulnerability in Jenkins Groovy Libraries
A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
network
low complexity
jenkins
critical
9.9
2022-10-19 CVE-2022-43405 Unspecified vulnerability in Jenkins Groovy Libraries
A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attackers with permission to define untrusted Pipeline libraries and to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
network
low complexity
jenkins
critical
9.9