Vulnerabilities > Jenkins > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-06-23 | CVE-2022-34195 | Cross-site Scripting vulnerability in Jenkins Repository Connector Jenkins Repository Connector Plugin 2.2.0 and earlier does not escape the name and description of Maven Repository Artifact parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | 5.4 |
2022-06-23 | CVE-2022-34196 | Cross-site Scripting vulnerability in Jenkins Rest List Parameter Jenkins REST List Parameter Plugin 1.5.2 and earlier does not escape the name and description of REST list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | 5.4 |
2022-06-23 | CVE-2022-34197 | Cross-site Scripting vulnerability in Jenkins Sauce Ondemand Jenkins Sauce OnDemand Plugin 1.204 and earlier does not escape the name and description of Sauce Labs Browsers parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | 5.4 |
2022-06-23 | CVE-2022-34198 | Cross-site Scripting vulnerability in Jenkins Stash Branch Parameter Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier does not escape the name and description of Stash Branch parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | 5.4 |
2022-06-23 | CVE-2022-34199 | Insufficiently Protected Credentials vulnerability in Jenkins Convertigo Mobile Platform 1.0/1.1 Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system. | 6.5 |
2022-06-23 | CVE-2022-34201 | Missing Authorization vulnerability in Jenkins Convertigo Mobile Platform 1.0/1.1 A missing permission check in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL. | 6.5 |
2022-06-23 | CVE-2022-34202 | Insufficiently Protected Credentials vulnerability in Jenkins Easyqa 1.0 Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | 6.5 |
2022-06-23 | CVE-2022-34204 | Missing Authorization vulnerability in Jenkins Easyqa 1.0 A missing permission check in Jenkins EasyQA Plugin 1.0 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server. | 4.3 |
2022-06-23 | CVE-2022-34205 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Jianliao Notification 1.0/1.1 A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers to send HTTP POST requests to an attacker-specified URL. | 6.5 |
2022-06-23 | CVE-2022-34206 | Missing Authorization vulnerability in Jenkins Jianliao Notification 1.0/1.1 A missing permission check in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers with Overall/Read permission to send HTTP POST requests to an attacker-specified URL. | 4.3 |