2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25199HIGH8.8A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission...
CVE-2022-25198HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers to co...
CVE-2022-25197MEDIUM6.5Jenkins HashiCorp Vault Plugin 336.v182c0fbaaeb7 and earlier implements functionality that allows agent processes to rea...
CVE-2022-25196MEDIUM5.4Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameter...
CVE-2022-25195MEDIUM4.3A missing permission check in Jenkins autonomiq Plugin 1.15 and earlier allows attackers with Overall/Read permission to...
CVE-2022-25194HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins autonomiq Plugin 1.15 and earlier allows attackers to conne...
CVE-2022-25193MEDIUM6.5Missing permission checks in Jenkins Snow Commander Plugin 1.10 and earlier allow attackers with Overall/Read permission...
CVE-2022-25192HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Snow Commander Plugin 1.10 and earlier allows attackers to ...
CVE-2022-25191MEDIUM5.4Jenkins Agent Server Parameter Plugin 1.0 and earlier does not escape parameter names of agent server parameters, result...
CVE-2022-25190MEDIUM4.3A missing permission check in Jenkins Conjur Secrets Plugin 1.0.11 and earlier allows attackers with Overall/Read permis...
CVE-2022-25189MEDIUM5.4Jenkins Custom Checkbox Parameter Plugin 1.1 and earlier does not escape parameter names of custom checkbox parameters, ...
CVE-2022-25188MEDIUM4.3Jenkins Fortify Plugin 20.2.34 and earlier does not sanitize the appName and appVersion parameters of its Pipeline steps...
CVE-2022-25187MEDIUM6.5Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.
CVE-2022-25186MEDIUM6.5Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Va...
CVE-2022-25185MEDIUM5.4Jenkins Generic Webhook Trigger Plugin 1.81 and earlier does not escape the build cause when using the webhook, resultin...
CVE-2022-25184MEDIUM6.5Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipelin...
CVE-2022-25183HIGH8.8Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to c...
CVE-2022-25182HIGH8.8A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows ...
CVE-2022-25181HIGH8.8A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows ...
CVE-2022-25180MEDIUM4.3Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in r...
CVE-2022-25179MEDIUM6.5Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the ch...
CVE-2022-25178MEDIUM6.5Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier does not restrict the names of resources ...
CVE-2022-25177MEDIUM6.5Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic links to locations outsi...
CVE-2022-25176MEDIUM6.5Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checko...
CVE-2022-25175HIGH8.8Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now