Vulnerabilities > Jenkins > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-03-29 CVE-2022-28157 Path Traversal vulnerability in Jenkins Pipeline: Phoenix Autotest
Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller via FTP to an attacker-specified FTP server.
network
low complexity
jenkins CWE-22
6.5
2022-03-29 CVE-2022-28158 Missing Authorization vulnerability in Jenkins Pipeline: Phoenix Autotest
A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
6.5
2022-03-29 CVE-2022-28159 Cross-site Scripting vulnerability in Jenkins Tests Selector
Jenkins Tests Selector Plugin 1.3.3 and earlier does not escape the Properties File Path option for Choosing Tests parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
network
low complexity
jenkins CWE-79
5.4
2022-03-29 CVE-2022-28160 Exposure of Resource to Wrong Sphere vulnerability in Jenkins Tests Selector
Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on the Jenkins controller.
network
low complexity
jenkins CWE-668
6.5
2022-03-15 CVE-2022-27195 Unspecified vulnerability in Jenkins Parameterized Trigger
Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files.
local
low complexity
jenkins
5.5
2022-03-15 CVE-2022-27196 Cross-site Scripting vulnerability in Jenkins Favorite
Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure or Item/Create permissions.
network
low complexity
jenkins CWE-79
5.4
2022-03-15 CVE-2022-27197 Cross-site Scripting vulnerability in Jenkins Dashboard View
Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure views.
network
low complexity
jenkins CWE-79
5.4
2022-03-15 CVE-2022-27199 Missing Authorization vulnerability in Jenkins Cloudbees AWS Credentials
A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token.
network
low complexity
jenkins CWE-862
4.3
2022-03-15 CVE-2022-27200 Cross-site Scripting vulnerability in Jenkins Folder-Based Authorization Strategy
Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the configuration form, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.
network
low complexity
jenkins CWE-79
4.8
2022-03-15 CVE-2022-27201 Unspecified vulnerability in Jenkins Semantic Versioning
Jenkins Semantic Versioning Plugin 1.13 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitations about the file path that can be parsed, allowing attackers able to control agent processes to have Jenkins parse a crafted file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
network
low complexity
jenkins
6.5