Vulnerabilities > Jenkins > High

DATE CVE VULNERABILITY TITLE RISK
2022-02-15 CVE-2022-25194 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Autonomiq
A cross-site request forgery (CSRF) vulnerability in Jenkins autonomiq Plugin 1.15 and earlier allows attackers to connect to an attacker-specified URL server using attacker-specified credentials.
network
low complexity
jenkins CWE-352
8.8
2022-02-15 CVE-2022-25198 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins SCP Publisher 1.8
A cross-site request forgery (CSRF) vulnerability in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.
network
low complexity
jenkins CWE-352
8.8
2022-02-15 CVE-2022-25199 Missing Authorization vulnerability in Jenkins SCP Publisher 1.8
A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.
network
low complexity
jenkins CWE-862
8.8
2022-02-15 CVE-2022-25200 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Checkmarx
A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-352
8.8
2022-02-15 CVE-2022-25205 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Dbcharts 0.4/0.5.2
A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine if a class is available in the Jenkins instance.
network
low complexity
jenkins CWE-352
8.8
2022-02-15 CVE-2022-25206 Missing Authorization vulnerability in Jenkins Dbcharts 0.4/0.5.2
A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified database via JDBC using attacker-specified credentials.
network
low complexity
jenkins CWE-862
8.8
2022-02-15 CVE-2022-25207 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Chef Sinatra
A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
network
low complexity
jenkins CWE-352
8.8
2022-02-15 CVE-2022-25208 Missing Authorization vulnerability in Jenkins Chef Sinatra
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
network
low complexity
jenkins CWE-862
8.8
2022-02-15 CVE-2022-25209 XXE vulnerability in Jenkins Chef Sinatra
Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
8.8
2022-02-15 CVE-2022-25211 Missing Authorization vulnerability in Jenkins Swamp
A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server using attacker-specified credentials.
network
low complexity
jenkins CWE-862
8.8