Vulnerabilities > Jenkins > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-06-23 CVE-2022-34195 Cross-site Scripting vulnerability in Jenkins Repository Connector
Jenkins Repository Connector Plugin 2.2.0 and earlier does not escape the name and description of Maven Repository Artifact parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
network
low complexity
jenkins CWE-79
5.4
2022-06-23 CVE-2022-34196 Cross-site Scripting vulnerability in Jenkins Rest List Parameter
Jenkins REST List Parameter Plugin 1.5.2 and earlier does not escape the name and description of REST list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
network
low complexity
jenkins CWE-79
5.4
2022-06-23 CVE-2022-34197 Cross-site Scripting vulnerability in Jenkins Sauce Ondemand
Jenkins Sauce OnDemand Plugin 1.204 and earlier does not escape the name and description of Sauce Labs Browsers parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
network
low complexity
jenkins CWE-79
5.4
2022-06-23 CVE-2022-34198 Cross-site Scripting vulnerability in Jenkins Stash Branch Parameter
Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier does not escape the name and description of Stash Branch parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
network
low complexity
jenkins CWE-79
5.4
2022-06-23 CVE-2022-34199 Insufficiently Protected Credentials vulnerability in Jenkins Convertigo Mobile Platform 1.0/1.1
Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
network
low complexity
jenkins CWE-522
6.5
2022-06-23 CVE-2022-34201 Missing Authorization vulnerability in Jenkins Convertigo Mobile Platform 1.0/1.1
A missing permission check in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
network
low complexity
jenkins CWE-862
6.5
2022-06-23 CVE-2022-34202 Insufficiently Protected Credentials vulnerability in Jenkins Easyqa 1.0
Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
network
low complexity
jenkins CWE-522
6.5
2022-06-23 CVE-2022-34204 Missing Authorization vulnerability in Jenkins Easyqa 1.0
A missing permission check in Jenkins EasyQA Plugin 1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server.
network
low complexity
jenkins CWE-862
4.3
2022-06-23 CVE-2022-34205 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Jianliao Notification 1.0/1.1
A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests to an attacker-specified URL.
network
low complexity
jenkins CWE-352
6.5
2022-06-23 CVE-2022-34206 Missing Authorization vulnerability in Jenkins Jianliao Notification 1.0/1.1
A missing permission check in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers with Overall/Read permission to send HTTP POST requests to an attacker-specified URL.
network
low complexity
jenkins CWE-862
4.3