2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25199 | HIGH | 8.8 | 0.8% | Feb 15, 2022 | A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission... |
| CVE-2022-25198 | HIGH | 8.8 | 0.5% | Feb 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers to co... |
| CVE-2022-25197 | MEDIUM | 6.5 | 0.8% | Feb 15, 2022 | Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements functionality that allows agent processes to rea... |
| CVE-2022-25196 | MEDIUM | 5.4 | 0.7% | Feb 15, 2022 | Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameter... |
| CVE-2022-25195 | MEDIUM | 4.3 | 0.5% | Feb 15, 2022 | A missing permission check in Jenkins autonomiq Plugin 1.15 and earlier allows attackers with Overall/Read permission to... |
| CVE-2022-25194 | HIGH | 8.8 | 0.5% | Feb 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins autonomiq Plugin 1.15 and earlier allows attackers to conne... |
| CVE-2022-25193 | MEDIUM | 6.5 | 0.9% | Feb 15, 2022 | Missing permission checks in Jenkins Snow Commander Plugin 1.10 and earlier allow attackers with Overall/Read permission... |
| CVE-2022-25192 | HIGH | 8.8 | 0.6% | Feb 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Snow Commander Plugin 1.10 and earlier allows attackers to ... |
| CVE-2022-25191 | MEDIUM | 5.4 | 0.6% | Feb 15, 2022 | Jenkins Agent Server Parameter Plugin 1.0 and earlier does not escape parameter names of agent server parameters, result... |
| CVE-2022-25190 | MEDIUM | 4.3 | 0.7% | Feb 15, 2022 | A missing permission check in Jenkins Conjur Secrets Plugin 1.0.11 and earlier allows attackers with Overall/Read permis... |
| CVE-2022-25189 | MEDIUM | 5.4 | 0.6% | Feb 15, 2022 | Jenkins Custom Checkbox Parameter Plugin 1.1 and earlier does not escape parameter names of custom checkbox parameters, ... |
| CVE-2022-25188 | MEDIUM | 4.3 | 1.2% | Feb 15, 2022 | Jenkins Fortify Plugin 20.2.34 and earlier does not sanitize the appName and appVersion parameters of its Pipeline steps... |
| CVE-2022-25187 | MEDIUM | 6.5 | 1.0% | Feb 15, 2022 | Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle. |
| CVE-2022-25186 | MEDIUM | 6.5 | 0.8% | Feb 15, 2022 | Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Va... |
| CVE-2022-25185 | MEDIUM | 5.4 | 0.6% | Feb 15, 2022 | Jenkins Generic Webhook Trigger Plugin 1.81 and earlier does not escape the build cause when using the webhook, resultin... |
| CVE-2022-25184 | MEDIUM | 6.5 | 0.9% | Feb 15, 2022 | Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipelin... |
| CVE-2022-25183 | HIGH | 8.8 | 1.5% | Feb 15, 2022 | Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to c... |
| CVE-2022-25182 | HIGH | 8.8 | 1.5% | Feb 15, 2022 | A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows ... |
| CVE-2022-25181 | HIGH | 8.8 | 1.5% | Feb 15, 2022 | A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows ... |
| CVE-2022-25180 | MEDIUM | 4.3 | 0.5% | Feb 15, 2022 | Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in r... |
| CVE-2022-25179 | MEDIUM | 6.5 | 1.8% | Feb 15, 2022 | Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the ch... |
| CVE-2022-25178 | MEDIUM | 6.5 | 1.6% | Feb 15, 2022 | Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier does not restrict the names of resources ... |
| CVE-2022-25177 | MEDIUM | 6.5 | 1.7% | Feb 15, 2022 | Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic links to locations outsi... |
| CVE-2022-25176 | MEDIUM | 6.5 | 1.7% | Feb 15, 2022 | Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checko... |
| CVE-2022-25175 | HIGH | 8.8 | 1.4% | Feb 15, 2022 | Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now